#17162 closed enhancement (fixed)

libksba-1.6.2

Reported by: Bruce Dubbs Owned by: Bruce Dubbs
Priority: elevated Milestone: 11.3
Component: BOOK Version: git
Severity: normal Keywords:
Cc:

Description

New point version.

Change History (5)

comment:1 by Bruce Dubbs, 19 months ago

Owner: changed from blfs-book to Bruce Dubbs
Status: newassigned

comment:2 by Bruce Dubbs, 19 months ago

Noteworthy changes in version 1.6.2 (2022-10-07)

  • Fix integer overflow in the CRL parser.

comment:3 by Bruce Dubbs, 19 months ago

Resolution: fixed
Status: assignedclosed

Fixed at commits

8aa560c873 Update to libgpg-error-1.46.
eaeb4f0f98 Update to libksba-1.6.2.
28ebeb0cea Update to btrfs-progs-v6.0.

comment:4 by ken@…, 18 months ago

Priority: normalelevated
Resolution: fixed
Status: closedreopened

The release of gnupg-2.3.8 is noted as fixing CVE-2022-3515 but in fact that fix is only in the binary downloads - linux distros and other 'nix systems use separate libksba which is where the fix is (presumably the integer overflow referred to above)

Upstream advisory is https://gnupg.org/blog/20221017-pepe-left-the-ksba.html and the CVE number is mentioned at https://www.mail-archive.com/gnupg-users@gnupg.org/msg40925.html

Reopening until I do the advisory, and will belatedly mark the change as a security fix.

comment:5 by ken@…, 18 months ago

Resolution: fixed
Status: reopenedclosed

Advisory SA 11.2-014.

Note: See TracTickets for help on using tickets.