Lucene search

K
osvGoogleOSV:DLA-470-1
HistoryMay 13, 2016 - 12:00 a.m.

libksba - security update

2016-05-1300:00:00
Google
osv.dev
10

EPSS

0.017

Percentile

87.9%

It was discovered that there was a possible read access beyond a buffer
vulnerability in libksba, a X.509 and CMS certificate support library.

The returned length of the object from _ksba_ber_parse_tl (ti.length)
was not always checked against the actual buffer length, thus leading
to a read access after the end of the buffer and thus a SEGV.

For Debian 7 Wheezy, this issue has been fixed in libksba version
1.2.0-2+deb7u2.

We recommend that you upgrade your libksba packages.