REDHAT-BUG-2161571: Integer Overflow
Libksba before 1.6.3 is prone to an integer overflow vulnerability in the CRL signature parser.
https://dev.gnupg.org/T6284 https://git.gnupg.org/cgi-bin/gitweb.cgi?p=libksba.git;a=commit;h=f61a5ea4e0f6a80fd4b28ef0174bee77793cf070 https://www.debian.org/security/2022/dsa-5305 https://lists.debian.org/debian-lts-announce/2022/12/msg00035.html https://security.gentoo.org/glsa/202212-07
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2161571?
The severity of REDHAT-BUG-2161571 is high due to the potential for integer overflow exploitation.
How do I fix REDHAT-BUG-2161571?
To fix REDHAT-BUG-2161571, update Libksba to version 1.6.3 or later.
Which versions of Libksba are affected by REDHAT-BUG-2161571?
Libksba versions prior to 1.6.3 are affected by REDHAT-BUG-2161571.
What kind of vulnerability is REDHAT-BUG-2161571?
REDHAT-BUG-2161571 is classified as an integer overflow vulnerability in the CRL signature parser.
Where can I find more information about REDHAT-BUG-2161571?
More information about REDHAT-BUG-2161571 can be found in the bug reports and commits related to Libksba.