Gnupg

Libksba

9 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.13%
  • Veröffentlicht 12.01.2023 15:15:10
  • Zuletzt bearbeitet 08.04.2025 16:15:19

A vulnerability was found in the Libksba library due to an integer overflow within the CRL parser. The vulnerability can be exploited remotely for code execution on the target system by passing specially crafted data to the application, for example, ...

  • EPSS 2.18%
  • Veröffentlicht 20.12.2022 23:15:12
  • Zuletzt bearbeitet 16.04.2025 18:16:02

Libksba before 1.6.3 is prone to an integer overflow vulnerability in the CRL signature parser.

  • EPSS 1.16%
  • Veröffentlicht 13.06.2016 19:59:10
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Libksba before 1.3.4 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via unspecified vectors, related to the "returned length of the object from _ksba_ber_parse_tl."

  • EPSS 0.96%
  • Veröffentlicht 13.06.2016 19:59:09
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Off-by-one error in the append_utf8_value function in the DN decoder (dn.c) in Libksba before 1.3.4 allows remote attackers to cause a denial of service (out-of-bounds read) via invalid utf-8 encoded data. NOTE: this vulnerability exists because of a...

  • EPSS 0.96%
  • Veröffentlicht 13.06.2016 19:59:06
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The append_utf8_value function in the DN decoder (dn.c) in Libksba before 1.3.3 allows remote attackers to cause a denial of service (out-of-bounds read) by clearing the high bit of the byte after invalid utf-8 encoded data.

  • EPSS 0.79%
  • Veröffentlicht 13.06.2016 19:59:05
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Multiple integer overflows in ber-decoder.c in Libksba before 1.3.3 allow remote attackers to cause a denial of service (crash) via crafted BER data, which leads to a buffer overflow.

  • EPSS 0.79%
  • Veröffentlicht 13.06.2016 19:59:04
  • Zuletzt bearbeitet 12.04.2025 10:46:40

ber-decoder.c in Libksba before 1.3.3 uses an incorrect integer data type, which allows remote attackers to cause a denial of service (crash) via crafted BER data, which leads to a buffer overflow.

  • EPSS 0.8%
  • Veröffentlicht 13.06.2016 19:59:03
  • Zuletzt bearbeitet 12.04.2025 10:46:40

ber-decoder.c in Libksba before 1.3.3 does not properly handle decoder stack overflows, which allows remote attackers to cause a denial of service (abort) via crafted BER data.

  • EPSS 7.75%
  • Veröffentlicht 01.12.2014 15:59:11
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Integer underflow in the ksba_oid_to_str function in Libksba before 1.3.2, as used in GnuPG, allows remote attackers to cause a denial of service (crash) via a crafted OID in a (1) S/MIME message or (2) ECC based OpenPGP data, which triggers a buffer...