CVE-2022-3515 is a critical integer overflow vulnerability in the Libksba library's CRL parser, affecting products such as gnupg and gpg4win. This flaw allows for remote code execution via specially crafted data, such as a malicious S/MIME attachment. With a CVSS score of 9.8 (CRITICAL), it poses a significant risk due to its network-based attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered some community discussion, including variant analysis leading to a related CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.6.3CPE matchmatch criteria | cpe:2.3:a:gnupg:libksba:*:*:*:*:*:*:*:* | ||
>= 2.0.0, < 4.1.0CPE matchmatch criteria | cpe:2.3:a:gpg4win:gpg4win:*:*:*:*:*:*:*:* | ||
>= 3.1.16, < 3.1.26CPE matchmatch criteria | cpe:2.3:a:gnupg:vs-desktop:*:*:*:*:*:*:*:* | ||
>= 2.1.0, < 2.2.41CPE matchmatch criteria | cpe:2.3:a:gnupg:gnupg:*:*:*:*:lts:*:*:* | ||
>= 2.3.0, < 2.4.0CPE matchmatch criteria | cpe:2.3:a:gnupg:gnupg:*:*:*:*:-:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2022-3515
Mar 14, 2023A vulnerability was found in the Libksba library due to an integer overflow within the CRL parser. The vulnerability can be exploited remotely for code execution on the target system by passing specially crafted data to the application for example a malicious S/MIME attachment.
Jan 10, 2023libksba: integer overflow may lead to remote code execution
Oct 17, 2022