Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-3515


A vulnerability was found in the Libksba library due to an integer overflow within the CRL parser. The vulnerability can be exploited remotely for code execution on the target system by passing specially crafted data to the application, for example, a malicious S/MIME attachment.


Published

2023-01-12T15:15:10.187

Last Modified

2025-04-08T16:15:19.830

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

Weaknesses
  • Type: Primary
    CWE-190
  • Type: Secondary
    CWE-190

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application gnupg libksba < 1.6.3 Yes
Application gpg4win gpg4win < 4.1.0 Yes
Application gnupg vs-desktop < 3.1.26 Yes
Application gnupg gnupg < 2.2.41 Yes
Application gnupg gnupg < 2.4.0 Yes

References