CVE-2022-23951: Medium severity keylime (keylime) vulnerability
Published Sep 21, 2022
·Updated
In Keylime before 6.3.0, quote responses from the agent can contain possibly untrusted ZIP data which can lead to zip bombs.
Affected Software
1 affected component
Keylime Keylime<6.3.0
Remediation
Patch Available
Event History
Sep 21, 2022
CVE Published
via MITRE·06:25 PM
Data Sourced
via MITRE·06:25 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability identifier for this Keylime vulnerability?
The vulnerability identifier for this Keylime vulnerability is CVE-2022-23951.
2
What is the impact of CVE-2022-23951?
CVE-2022-23951 can lead to zip bombs, potentially causing denial of service or resource exhaustion.
3
What is the severity of CVE-2022-23951?
The severity of CVE-2022-23951 is rated as medium with a CVSS score of 5.5.
4
How can I fix CVE-2022-23951 in Keylime?
To fix CVE-2022-23951 in Keylime, update to version 6.3.0 or later.
5
Where can I find more information about CVE-2022-23951?
You can find more information about CVE-2022-23951 on the Keylime GitHub advisory page and the OSS Security mailing list.