Gnupg Libksba
By the Year
In 2024 there have been 0 vulnerabilities in Gnupg Libksba . Last year Libksba had 1 security vulnerability published. Right now, Libksba is on track to have less security vulnerabilities in 2024 than it did last year.
Year | Vulnerabilities | Average Score |
---|---|---|
2024 | 0 | 0.00 |
2023 | 1 | 9.80 |
2022 | 1 | 9.80 |
2021 | 0 | 0.00 |
2020 | 0 | 0.00 |
2019 | 0 | 0.00 |
2018 | 0 | 0.00 |
It may take a day or so for new Libksba vulnerabilities to show up in the stats or in the list of recent security vulnerabilties. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Gnupg Libksba Security Vulnerabilities
A vulnerability was found in the Libksba library due to an integer overflow within the CRL parser
CVE-2022-3515
9.8 - Critical
- January 12, 2023
A vulnerability was found in the Libksba library due to an integer overflow within the CRL parser. The vulnerability can be exploited remotely for code execution on the target system by passing specially crafted data to the application, for example, a malicious S/MIME attachment.
Libksba before 1.6.3 is prone to an integer overflow vulnerability in the CRL signature parser.
CVE-2022-47629
9.8 - Critical
- December 20, 2022
Libksba before 1.6.3 is prone to an integer overflow vulnerability in the CRL signature parser.
Integer Overflow or Wraparound
Libksba before 1.3.4
CVE-2016-4579
7.5 - High
- June 13, 2016
Libksba before 1.3.4 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via unspecified vectors, related to the "returned length of the object from _ksba_ber_parse_tl."
Improper Input Validation
Off-by-one error in the append_utf8_value function in the DN decoder (dn.c) in Libksba before 1.3.4
CVE-2016-4574
7.5 - High
- June 13, 2016
Off-by-one error in the append_utf8_value function in the DN decoder (dn.c) in Libksba before 1.3.4 allows remote attackers to cause a denial of service (out-of-bounds read) via invalid utf-8 encoded data. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-4356.
Numeric Errors
The append_utf8_value function in the DN decoder (dn.c) in Libksba before 1.3.3
CVE-2016-4356
7.5 - High
- June 13, 2016
The append_utf8_value function in the DN decoder (dn.c) in Libksba before 1.3.3 allows remote attackers to cause a denial of service (out-of-bounds read) by clearing the high bit of the byte after invalid utf-8 encoded data.
Buffer Overflow
Multiple integer overflows in ber-decoder.c in Libksba before 1.3.3
CVE-2016-4355
7.5 - High
- June 13, 2016
Multiple integer overflows in ber-decoder.c in Libksba before 1.3.3 allow remote attackers to cause a denial of service (crash) via crafted BER data, which leads to a buffer overflow.
Buffer Overflow
ber-decoder.c in Libksba before 1.3.3 uses an incorrect integer data type, which
CVE-2016-4354
7.5 - High
- June 13, 2016
ber-decoder.c in Libksba before 1.3.3 uses an incorrect integer data type, which allows remote attackers to cause a denial of service (crash) via crafted BER data, which leads to a buffer overflow.
Buffer Overflow
ber-decoder.c in Libksba before 1.3.3 does not properly handle decoder stack overflows, which
CVE-2016-4353
7.5 - High
- June 13, 2016
ber-decoder.c in Libksba before 1.3.3 does not properly handle decoder stack overflows, which allows remote attackers to cause a denial of service (abort) via crafted BER data.
Improper Input Validation
Integer underflow in the ksba_oid_to_str function in Libksba before 1.3.2, as used in GnuPG
CVE-2014-9087
- December 01, 2014
Integer underflow in the ksba_oid_to_str function in Libksba before 1.3.2, as used in GnuPG, allows remote attackers to cause a denial of service (crash) via a crafted OID in a (1) S/MIME message or (2) ECC based OpenPGP data, which triggers a buffer overflow.
Integer underflow
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Gnupg Libksba or by Gnupg? Click the Watch button to subscribe.