CVE-2016-4574

Source
https://nvd.nist.gov/vuln/detail/CVE-2016-4574
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-4574.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2016-4574
Related
Published
2016-06-13T19:59:09Z
Modified
2024-09-18T02:25:51.302849Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

Off-by-one error in the appendutf8value function in the DN decoder (dn.c) in Libksba before 1.3.4 allows remote attackers to cause a denial of service (out-of-bounds read) via invalid utf-8 encoded data. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-4356.

References

Affected packages

Debian:11 / libksba

Package

Name
libksba
Purl
pkg:deb/debian/libksba?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.3.4-3

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12 / libksba

Package

Name
libksba
Purl
pkg:deb/debian/libksba?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.3.4-3

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / libksba

Package

Name
libksba
Purl
pkg:deb/debian/libksba?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.3.4-3

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Git / github.com/gpg/libksba

Affected ranges

Type
GIT
Repo
https://github.com/gpg/libksba
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected

Affected versions

Other

debian/V0-0-0
debian/V0-2-0
debian/V0-2-1
debian/V0-2-2
debian/V0-2-3
debian/V0-4-0
debian/V0-4-1
debian/V0-4-2
debian/V0-4-3
debian/V0-4-4
debian/V0-4-5
debian/libksba-0-4-6
debian/libksba-0-4-7
debian/libksba-0-9-0
debian/libksba-0-9-1
debian/libksba-0-9-10
debian/libksba-0-9-11
debian/libksba-0-9-12
debian/libksba-0-9-2
debian/libksba-0-9-3
debian/libksba-0-9-4
debian/libksba-0-9-5
debian/libksba-0-9-6
debian/libksba-0-9-7
debian/libksba-0-9-8
debian/libksba-0-9-9

debian/libksba-0.*

debian/libksba-0.9.13
debian/libksba-0.9.14
debian/libksba-0.9.15
debian/libksba-0.9.16

debian/libksba-1.*

debian/libksba-1.0.1
debian/libksba-1.0.2
debian/libksba-1.0.3
debian/libksba-1.0.4
debian/libksba-1.0.5
debian/libksba-1.0.6
debian/libksba-1.0.7
debian/libksba-1.0.8
debian/libksba-1.1.0

libksba-1.*

libksba-1.2.0
libksba-1.3.0
libksba-1.3.1
libksba-1.3.2
libksba-1.3.3