CVE-2022-3515

high
Published 2022-10-24 Β· Modified 2022-10-24
CVSS v3
β€”
CVSS v4 NEW
β€”
not yet in upstream
VIR risk
8.0

Description

A vulnerability was found in the Libksba library due to an integer overflow within the CRL parser. The vulnerability can be exploited remotely for code execution on the target system by passing specially crafted data to the application, for example, a malicious S/MIME attachment.

Predictions

Exploit likelihood
20%
Patch ETA
β€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Red Hat Errata β€” Red Hat Inc. Β· View original β†— Β· Open-Errata-API

Description libksba: integer overflow may lead to remote code execution CVSS v3: 8.6 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H) Errata / fixed releases ProductPackageAdvisoryReleased Red Hat Enterprise Linux 7libksba-0:1.3.0-6.el7_9RHSA-2022:70882022-10-24T00:00:00Z Red Hat Enterprise Linux 8libksba-0:1.3.5-8.el8_6RHSA-2022:70892022-10-24T00:00:00Z Red Hat Enterprise Linux 8.1 Update Services…

Description

libksba: integer overflow may lead to remote code execution

CVSS v3: 8.6 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H)

Errata / fixed releases

ProductPackageAdvisoryReleased
Red Hat Enterprise Linux 7libksba-0:1.3.0-6.el7_9RHSA-2022:70882022-10-24T00:00:00Z
Red Hat Enterprise Linux 8libksba-0:1.3.5-8.el8_6RHSA-2022:70892022-10-24T00:00:00Z
Red Hat Enterprise Linux 8.1 Update Services for SAP Solutionslibksba-0:1.3.5-8.el8_1RHSA-2022:72092022-10-26T00:00:00Z
Red Hat Enterprise Linux 8.2 Advanced Update Supportlibksba-0:1.3.5-8.el8_2RHSA-2022:72832022-11-01T00:00:00Z
Red Hat Enterprise Linux 8.2 Telecommunications Update Servicelibksba-0:1.3.5-8.el8_2RHSA-2022:72832022-11-01T00:00:00Z
Red Hat Enterprise Linux 8.2 Update Services for SAP Solutionslibksba-0:1.3.5-8.el8_2RHSA-2022:72832022-11-01T00:00:00Z
Red Hat Enterprise Linux 8.4 Extended Update Supportlibksba-0:1.3.5-8.el8_4RHSA-2022:79272022-11-14T00:00:00Z
Red Hat Enterprise Linux 9libksba-0:1.5.1-5.el9_0RHSA-2022:70902022-10-24T00:00:00Z
Red Hat Virtualization 4 for Red Hat Enterprise Linux 8redhat-virtualization-host-0:4.5.3-202211170828_8.6RHSA-2022:85982022-11-22T00:00:00Z

Package state

ProductPackageState
Red Hat Enterprise Linux 6libksbaOut of support scope

Apply commands

bash fix
Apply RHSA-2022:7088 for Red Hat Enterprise Linux 7
yum update -y libksba
# or:
dnf upgrade -y libksba

OS impact

suse SUSE Affected 1 release
VersionStatusFixed in
β€” Affected β€”
arch Arch Fixed 1 release
VersionStatusFixed in
β€” Fixed 1.6.3-1
debian Debian Fixed 5 releases
VersionStatusFixed in
trixie Fixed 1.6.2-1
sid Fixed 1.6.2-1
forky Fixed 1.6.2-1
bullseye Fixed 1.5.0-3+deb11u1
bookworm Fixed 1.6.2-1
redhat Red Hat Fixed 2 releases
VersionStatusFixed in
9 Fixed β€”
8 Fixed β€”
rockylinux Rocky Linux Fixed 2 releases
VersionStatusFixed in
9 Fixed β€”
8 Fixed β€”

References

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.