发布时间: 2022年10月28日
修改时间: 2024年10月31日
A bug found in libksba, the library used by GnuPG for parsing the ASN.1 structures as used by S/MIME. The bug affects all versions of Libksba before 1.6.2 and may be used for remote code execution. https://www.gnupg.org/blog/20221017-pepe-left-the-ksba.htmlhttps://dev.gnupg.org/T6230https://dev.gnupg.org/rK4b7d9cd4a018898d7714ce06f3faf2626c14582bhttps://lwn.net/Articles/911467/
NVD | openEuler | |
---|---|---|
Confidentiality | High | High |
Attack Vector | Network | Network |
CVSS评分 | 9.8 | 8.1 |
Attack Complexity | Low | High |
Privileges Required | None | None |
Scope | Unchanged | Unchanged |
Integrity | High | High |
User Interaction | None | None |
Availability | High | High |
公告名 | 概要 | 发布时间 |
---|---|---|
KylinSec-SA-2022-2562 | libksba security update | 2022年10月28日 |
产品 | 包 | 状态 |
---|---|---|
KY3.4-4A | libksba | Fixed |
KY3.4-5 | libksba | Fixed |
KY3.5.1 | libksba | Fixed |