Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

Mageia 8: MGASA-2022-0485 Moderate: Libksba Integer Overflow

mageia
Calendar Grey December 30, 2022
Dist Mageia Esm H88
MGASA-2022-0486: Revised libksba packages resolve a buffer overflow vulnerability on Mageia 8.
Libksba before 1.6.3 is prone to an integer overflow vulnerability in the CRL signature parser

Summary

Libksba before 1.6.3 is prone to an integer overflow vulnerability in the CRL signature parser. (CVE-2022-47629)

References

- https://bugs.mageia.org/show_bug.cgi?id=31311

- https://www.gnupg.org/blog/20221017-pepe-left-the-ksba.html

- https://lists.debian.org/debian-security-announce/2022/msg00276.html

- https://www.cve.org/CVERecord?id=CVE-2022-47629

Resolution

SRPMS

- 8/core/libksba-1.5.0-1.2.mga8

Severity
important
Lowest
Low
Medium
High
Critical

Publication date: 30 Dec 2022
URL: https://advisories.mageia.org/MGASA-2022-0485.html
Type: security
CVE: CVE-2022-47629

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here