Vulnerability Database
Blog
FAQ
Docs
CVE-2022-47629
See a problem?
Source
https://nvd.nist.gov/vuln/detail/CVE-2022-47629
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-47629.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-47629
Related
ALSA-2023:0625
ALSA-2023:0626
CGA-h347-jgp6-x43h
DLA-3248-1
DSA-5305-1
RLSA-2023:0625
RLSA-2023:0626
USN-5787-1
USN-5787-2
Published
2022-12-20T23:15:12Z
Modified
2024-09-03T04:24:14.208446Z
Severity
9.8 (Critical)
CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Calculator
Summary
[none]
Details
Libksba before 1.6.3 is prone to an integer overflow vulnerability in the CRL signature parser.
References
https://security.gentoo.org/glsa/202212-07
https://security.netapp.com/advisory/ntap-20230316-0011/
https://www.debian.org/security/2022/dsa-5305
https://lists.debian.org/debian-lts-announce/2022/12/msg00035.html
https://dev.gnupg.org/T6284
https://git.gnupg.org/cgi-bin/gitweb.cgi?p=libksba.git%3Ba=commit%3Bh=f61a5ea4e0f6a80fd4b28ef0174bee77793cf070
https://security.alpinelinux.org/vuln/CVE-2022-47629
Affected packages
Alpine:v3.14
/
libksba
Package
Name
libksba
Purl
pkg:apk/alpine/libksba?arch=source
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
1.5.1-r1
Affected versions
1.*
1.0.3-r0
1.0.3-r1
1.0.7-r0
1.0.7-r1
1.0.7-r2
1.0.8-r0
1.0.8-r1
1.0.8-r2
1.2.0-r0
1.3.0-r0
1.3.2-r0
1.3.3-r0
1.3.4-r0
1.3.5-r0
1.4.0-r0
1.5.0-r0
1.5.1-r0
Alpine:v3.15
/
libksba
Package
Name
libksba
Purl
pkg:apk/alpine/libksba?arch=source
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
1.6.3-r0
Affected versions
1.*
1.0.3-r0
1.0.3-r1
1.0.7-r0
1.0.7-r1
1.0.7-r2
1.0.8-r0
1.0.8-r1
1.0.8-r2
1.2.0-r0
1.3.0-r0
1.3.2-r0
1.3.3-r0
1.3.4-r0
1.3.5-r0
1.4.0-r0
1.5.0-r0
1.5.1-r0
1.6.0-r0
Alpine:v3.16
/
libksba
Package
Name
libksba
Purl
pkg:apk/alpine/libksba?arch=source
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
1.6.3-r0
Affected versions
1.*
1.0.3-r0
1.0.3-r1
1.0.7-r0
1.0.7-r1
1.0.7-r2
1.0.8-r0
1.0.8-r1
1.0.8-r2
1.2.0-r0
1.3.0-r0
1.3.2-r0
1.3.3-r0
1.3.4-r0
1.3.5-r0
1.4.0-r0
1.5.0-r0
1.5.1-r0
1.6.0-r0
Alpine:v3.17
/
libksba
Package
Name
libksba
Purl
pkg:apk/alpine/libksba?arch=source
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
1.6.3-r0
Affected versions
1.*
1.0.3-r0
1.0.3-r1
1.0.7-r0
1.0.7-r1
1.0.7-r2
1.0.8-r0
1.0.8-r1
1.0.8-r2
1.2.0-r0
1.3.0-r0
1.3.2-r0
1.3.3-r0
1.3.4-r0
1.3.5-r0
1.4.0-r0
1.5.0-r0
1.5.1-r0
1.6.0-r0
1.6.1-r0
1.6.2-r0
Alpine:v3.18
/
libksba
Package
Name
libksba
Purl
pkg:apk/alpine/libksba?arch=source
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
1.6.3-r0
Affected versions
1.*
1.0.3-r0
1.0.3-r1
1.0.7-r0
1.0.7-r1
1.0.7-r2
1.0.8-r0
1.0.8-r1
1.0.8-r2
1.2.0-r0
1.3.0-r0
1.3.2-r0
1.3.3-r0
1.3.4-r0
1.3.5-r0
1.4.0-r0
1.5.0-r0
1.5.1-r0
1.6.0-r0
1.6.1-r0
1.6.2-r0
Alpine:v3.19
/
libksba
Package
Name
libksba
Purl
pkg:apk/alpine/libksba?arch=source
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
1.6.3-r0
Affected versions
1.*
1.0.3-r0
1.0.3-r1
1.0.7-r0
1.0.7-r1
1.0.7-r2
1.0.8-r0
1.0.8-r1
1.0.8-r2
1.2.0-r0
1.3.0-r0
1.3.2-r0
1.3.3-r0
1.3.4-r0
1.3.5-r0
1.4.0-r0
1.5.0-r0
1.5.1-r0
1.6.0-r0
1.6.1-r0
1.6.2-r0
Alpine:v3.20
/
libksba
Package
Name
libksba
Purl
pkg:apk/alpine/libksba?arch=source
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
1.6.3-r0
Affected versions
1.*
1.0.3-r0
1.0.3-r1
1.0.7-r0
1.0.7-r1
1.0.7-r2
1.0.8-r0
1.0.8-r1
1.0.8-r2
1.2.0-r0
1.3.0-r0
1.3.2-r0
1.3.3-r0
1.3.4-r0
1.3.5-r0
1.4.0-r0
1.5.0-r0
1.5.1-r0
1.6.0-r0
1.6.1-r0
1.6.2-r0
Git
/
github.com/gpg/libksba
Affected ranges
Type
GIT
Repo
https://github.com/gpg/libksba
Events
Introduced
0
Unknown introduced commit / All previous commits are affected
Fixed
bffa9b346071725363a483db547e7dced9721cb5
Affected versions
Other
debian/V0-0-0
debian/V0-2-0
debian/V0-2-1
debian/V0-2-2
debian/V0-2-3
debian/V0-4-0
debian/V0-4-1
debian/V0-4-2
debian/V0-4-3
debian/V0-4-4
debian/V0-4-5
debian/libksba-0-4-6
debian/libksba-0-4-7
debian/libksba-0-9-0
debian/libksba-0-9-1
debian/libksba-0-9-10
debian/libksba-0-9-11
debian/libksba-0-9-12
debian/libksba-0-9-2
debian/libksba-0-9-3
debian/libksba-0-9-4
debian/libksba-0-9-5
debian/libksba-0-9-6
debian/libksba-0-9-7
debian/libksba-0-9-8
debian/libksba-0-9-9
debian/libksba-0.*
debian/libksba-0.9.13
debian/libksba-0.9.14
debian/libksba-0.9.15
debian/libksba-0.9.16
debian/libksba-1.*
debian/libksba-1.0.1
debian/libksba-1.0.2
debian/libksba-1.0.3
debian/libksba-1.0.4
debian/libksba-1.0.5
debian/libksba-1.0.6
debian/libksba-1.0.7
debian/libksba-1.0.8
debian/libksba-1.1.0
libksba-1.*
libksba-1.2.0
libksba-1.3.0
libksba-1.3.1
libksba-1.3.2
libksba-1.3.3
libksba-1.3.4
libksba-1.3.5
libksba-1.4.0
libksba-1.5.0
libksba-1.5.1
libksba-1.6.0
libksba-1.6.1
libksba-1.6.2
CVE-2022-47629 - OSV