Integer underflow in the ksba_oid_to_str function in Libksba before 1.3.2, as used in GnuPG, allows remote attackers to cause a denial of service (crash) via a crafted OID in a (1) S/MIME message or (2) ECC based OpenPGP data, which triggers a buffer overflow.
CVSS Details
- CVSS 3.1 Base Score: 7.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade libksba | Jul 30, 2024 | Dec 1, 2014 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Nov 25, 2014 |
| Suse | — | Upgrade libksba8Upgrade libksba-develUpgrade libksba | Dec 18, 2015 | Dec 1, 2014 |
| Ubuntu | — | Upgrade libksba8 | Nov 8, 2024 | Dec 1, 2014 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub