« List of all CVEs

CVE-2022-3515

Published: 1/12/2023 Last updated: 4/8/2025 Reserved: 10/14/2022

A vulnerability was found in the Libksba library due to an integer overflow within the CRL parser. The vulnerability can be exploited remotely for code execution on the target system by passing specially crafted data to the application, for example, a malicious S/MIME attachment.

CNA assigner: redhat (53f830b8-0a3f-465b-8143-3b8a9948e749) Requested by: n/a

Metrics

Version Score Severity Vector String
3.1 9.8 Critical CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Opam packages affected (1)

0install

Products affected (1)

Product Vendor Version
libksba n/a 23.0 ap383147

References (10)