CVE-2022-3515

A vulnerability was found in the Libksba library due to an integer overflow within the CRL parser. The vulnerability can be exploited remotely for code execution on the target system by passing specially crafted data to the application, for example, a malicious S/MIME attachment.
Configurations

Configuration 1 (hide)

cpe:2.3:a:gnupg:libksba:*:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:a:gpg4win:gpg4win:*:*:*:*:*:*:*:*

Configuration 3 (hide)

cpe:2.3:a:gnupg:vs-desktop:*:*:*:*:*:*:*:*

Configuration 4 (hide)

OR cpe:2.3:a:gnupg:gnupg:*:*:*:*:lts:*:*:*
cpe:2.3:a:gnupg:gnupg:*:*:*:*:-:*:*:*

History

21 Nov 2024, 07:19

Type Values Removed Values Added
References () https://access.redhat.com/security/cve/CVE-2022-3515 - Patch, Third Party Advisory () https://access.redhat.com/security/cve/CVE-2022-3515 - Patch, Third Party Advisory
References () https://bugzilla.redhat.com/show_bug.cgi?id=2135610 - Exploit, Issue Tracking, Third Party Advisory () https://bugzilla.redhat.com/show_bug.cgi?id=2135610 - Exploit, Issue Tracking, Third Party Advisory
References () https://dev.gnupg.org/rK4b7d9cd4a018898d7714ce06f3faf2626c14582b - Exploit, Patch, Third Party Advisory () https://dev.gnupg.org/rK4b7d9cd4a018898d7714ce06f3faf2626c14582b - Exploit, Patch, Third Party Advisory
References () https://security.netapp.com/advisory/ntap-20230706-0008/ - () https://security.netapp.com/advisory/ntap-20230706-0008/ -
References () https://www.gnupg.org/blog/20221017-pepe-left-the-ksba.html - Third Party Advisory () https://www.gnupg.org/blog/20221017-pepe-left-the-ksba.html - Third Party Advisory

06 Jul 2023, 19:15

Type Values Removed Values Added
References
  • (CONFIRM) https://security.netapp.com/advisory/ntap-20230706-0008/ -
CWE CWE-190

18 May 2023, 18:08

Type Values Removed Values Added
CPE cpe:2.3:a:libksba_project:libksba:*:*:*:*:*:*:*:* cpe:2.3:a:gnupg:libksba:*:*:*:*:*:*:*:*
First Time Gnupg libksba

Information

Published : 2023-01-12 15:15

Updated : 2025-04-08 16:15


NVD link : CVE-2022-3515

Mitre link : CVE-2022-3515

CVE.ORG link : CVE-2022-3515


JSON object : View

Products Affected

gnupg

  • libksba
  • gnupg
  • vs-desktop

gpg4win

  • gpg4win
CWE
CWE-190

Integer Overflow or Wraparound