QID 355054

Date Published: 2023-05-18

QID 355054: Amazon Linux Security Advisory for libksba : AL2012-2022-378

Package updates are available for Amazon Linux that fix the following vulnerabilities:
CVE-2022-3515:
A vulnerability was found in the Libksba library due to an integer overflow within the CRL parser. The vulnerability can be exploited remotely for code execution on the target system by passing specially crafted data to the application, for example, a malicious S/MIME attachment. 2135610: CVE-2022-3515 libksba: integer overflow may lead to remote code execution

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as Medium - 5.4 severity.
  • Solution
    Administrators are advised to apply the appropriate software updates.
    Vendor References

    CVEs related to QID 355054

    Software Advisories
    Advisory ID Software Component Link
    AL2012-2022-378 Amazon Linux Bare Metal URL Logo docs.aws.amazon.com/AWSEC2/latest/UserGuide/install-updates.html