CVE-2022-3515
CRITICALLibksba < 1.6.3 - Remote Code Execution via CRL Parser Integer Overflow
Title source: llmDescription
A vulnerability was found in the Libksba library due to an integer overflow within the CRL parser. The vulnerability can be exploited remotely for code execution on the target system by passing specially crafted data to the application, for example, a malicious S/MIME attachment.
References (5)
Core 5
Core References
Patch, Third Party Advisory
https://access.redhat.com/security/cve/CVE-2022-3515
Exploit, Issue Tracking, Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=2135610
Exploit, Patch, Third Party Advisory
https://dev.gnupg.org/rK4b7d9cd4a018898d7714ce06f3faf2626c14582b
Third Party Advisory
https://www.gnupg.org/blog/20221017-pepe-left-the-ksba.html
Vendor Advisory
https://security.netapp.com/advisory/ntap-20230706-0008/
Scores
CVSS v3
9.8
EPSS
0.0163
EPSS Percentile
73.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
total
Details
CWE
CWE-190
Status
published
Products (5)
gnupg/gnupg
2.1.0 - 2.2.41
gnupg/gnupg
2.3.0 - 2.4.0
gnupg/libksba
< 1.6.3
gnupg/vs-desktop
3.1.16 - 3.1.26
gpg4win/gpg4win
2.0.0 - 4.1.0
Published
Jan 12, 2023
Tracked Since
Feb 18, 2026