CVE-2022-47629: Integer Overflow
A vulnerability was found in the Libksba library, due to an integer overflow within the CRL's signature parser. This issue can be exploited remotely for code execution on the target system by passing specially crafted data to the application, for example, a malicious S/MIME attachment.
Other sources
Libksba before 1.6.3 is prone to an integer overflow vulnerability in the CRL signature parser.
Affected Software
Remediation
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2022-47629?
CVE-2022-47629 is a vulnerability found in the Libksba library, which is prone to an integer overflow vulnerability in the CRL signature parser.
How severe is CVE-2022-47629?
CVE-2022-47629 has a severity rating of 9.8 (Critical).
How does CVE-2022-47629 affect the Libksba library?
CVE-2022-47629 affects the Libksba library by allowing remote attackers to execute code on the target system by passing specially crafted data.
Which software versions are affected by CVE-2022-47629?
The affected software versions include Libksba 1.3.5-2+deb10u2, 1.5.0-3+deb11u2, 1.6.3-2, and 1.6.4-2.
How can I fix CVE-2022-47629?
To fix CVE-2022-47629, it is recommended to update the Libksba library to version 1.6.3 or higher.