Lucene search

K
amazonAmazonALAS-2023-1752
HistoryMay 25, 2023 - 5:41 p.m.

Important: libksba

2023-05-2517:41:00
alas.aws.amazon.com
3
libksba
integer overflow
vulnerability
signature parser
update
system
red hat
mitre
unix

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

0.003 Low

EPSS

Percentile

65.8%

Issue Overview:

Libksba before 1.6.3 is prone to an integer overflow vulnerability in the CRL signature parser. (CVE-2022-47629)

Affected Packages:

libksba

Issue Correction:
Run yum update libksba to update your system.

New Packages:

i686:  
    libksba-devel-1.3.5-1.11.amzn1.i686  
    libksba-1.3.5-1.11.amzn1.i686  
    libksba-debuginfo-1.3.5-1.11.amzn1.i686  
  
src:  
    libksba-1.3.5-1.11.amzn1.src  
  
x86_64:  
    libksba-debuginfo-1.3.5-1.11.amzn1.x86_64  
    libksba-devel-1.3.5-1.11.amzn1.x86_64  
    libksba-1.3.5-1.11.amzn1.x86_64  

Additional References

Red Hat: CVE-2022-47629

Mitre: CVE-2022-47629

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

0.003 Low

EPSS

Percentile

65.8%