CRITICAL 9.8 Microsoft
CVE-2022-3515
A vulnerability was found in the Libksba library due to an integer overflow within the CRL parser. The vulnerability can be exploited remotely for code execution on the target system by passing specially crafted data to the application for example a malicious S/MIME attachment.
Microsoft Security Update 2023-Jan: A vulnerability was found in the Libksba library due to an integer overflow within the CRL parser. The vulnerability can be exploited remotely for code execution on the target system by passing specially crafted data to the application for example a malicious S/MIME attachment.
Affected Products
- cm1 libksba 1.3.5-5 on CBL Mariner 1.0
- cm1 gnupg2 2.2.20-4 on CBL Mariner 1.0
- cbl2 gnupg2 2.4.0-1 on CBL Mariner 2.0
References
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-3515
- https://nvd.nist.gov/vuln/detail/CVE-2022-3515
This critical severity vulnerability with a CVSS score of 9.8 was published on 2023-01-10 via Microsoft. Affected: cm1 libksba 1.3.5-5 on CBL Mariner 1.0, cm1 gnupg2 2.2.20-4 on CBL Mariner 1.0, cbl2 gnupg2 2.4.0-1 on CBL Mariner 2.0.
Risk Timeline
CVE Disclosed2023-01-10 · 1301 days ago
Remediation Resources
Official Advisory
msrc.microsoft.com/update-guide/vulnerability/CVE-2022-3515NVD / MITRE
nvd.nist.gov/vuln/detail/CVE-2022-3515Related Vulnerabilities
| CVE | Title | Severity | CVSS |
|---|---|---|---|
| CVE-2022-4338 | An integer underflow in Organization Specific TLV was found in various versions | CRITICAL | 9.8 |
| CVE-2022-41903 PoC | Integer overflow in `git archive` `git log --format` leading to RCE in git | CRITICAL | 9.8 |
| CVE-2022-4337 | An out-of-bounds read in Organization Specific TLV was found in various versions | CRITICAL | 9.8 |
| CVE-2022-36760 | Apache HTTP Server: mod_proxy_ajp Possible request smuggling | CRITICAL | 9.0 |
| CVE-2022-2196 | Speculative execution attacks in KVM VMX | HIGH | 8.8 |
| CVE-2023-0051 | Heap-based Buffer Overflow in vim/vim | HIGH | 7.8 |
vulnfeed aggregates 9166 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.