{
  "threat_severity" : "Important",
  "public_date" : "2022-10-17T00:00:00Z",
  "bugzilla" : {
    "description" : "libksba: integer overflow to code execution",
    "id" : "2161571",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2161571"
  },
  "cvss3" : {
    "cvss3_base_score" : "8.6",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H",
    "status" : "verified"
  },
  "cwe" : "CWE-190",
  "details" : [ "Libksba before 1.6.3 is prone to an integer overflow vulnerability in the CRL signature parser.", "A vulnerability was found in the Libksba library, due to an integer overflow within the CRL's signature parser. This issue can be exploited remotely for code execution on the target system by passing specially crafted data to the application, for example, a malicious S/MIME attachment." ],
  "affected_release" : [ {
    "product_name" : "Red Hat Enterprise Linux 7",
    "release_date" : "2023-01-30T00:00:00Z",
    "advisory" : "RHSA-2023:0530",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7",
    "package" : "libksba-0:1.3.0-7.el7_9"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "release_date" : "2023-02-07T00:00:00Z",
    "advisory" : "RHSA-2023:0625",
    "cpe" : "cpe:/o:redhat:enterprise_linux:8",
    "package" : "libksba-0:1.3.5-9.el8_7"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions",
    "release_date" : "2023-02-06T00:00:00Z",
    "advisory" : "RHSA-2023:0593",
    "cpe" : "cpe:/o:redhat:rhel_e4s:8.1",
    "package" : "libksba-0:1.3.5-9.el8_1"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.2 Advanced Update Support",
    "release_date" : "2023-02-06T00:00:00Z",
    "advisory" : "RHSA-2023:0592",
    "cpe" : "cpe:/o:redhat:rhel_aus:8.2",
    "package" : "libksba-0:1.3.5-9.el8_2"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.2 Telecommunications Update Service",
    "release_date" : "2023-02-06T00:00:00Z",
    "advisory" : "RHSA-2023:0592",
    "cpe" : "cpe:/o:redhat:rhel_tus:8.2",
    "package" : "libksba-0:1.3.5-9.el8_2"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions",
    "release_date" : "2023-02-06T00:00:00Z",
    "advisory" : "RHSA-2023:0592",
    "cpe" : "cpe:/o:redhat:rhel_e4s:8.2",
    "package" : "libksba-0:1.3.5-9.el8_2"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.4 Extended Update Support",
    "release_date" : "2023-02-07T00:00:00Z",
    "advisory" : "RHSA-2023:0624",
    "cpe" : "cpe:/o:redhat:rhel_eus:8.4",
    "package" : "libksba-0:1.3.5-9.el8_4"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.6 Extended Update Support",
    "release_date" : "2023-02-06T00:00:00Z",
    "advisory" : "RHSA-2023:0594",
    "cpe" : "cpe:/o:redhat:rhel_eus:8.6",
    "package" : "libksba-0:1.3.5-9.el8_6"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "release_date" : "2023-02-07T00:00:00Z",
    "advisory" : "RHSA-2023:0626",
    "cpe" : "cpe:/o:redhat:enterprise_linux:9",
    "package" : "libksba-0:1.5.1-6.el9_1"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9.0 Extended Update Support",
    "release_date" : "2023-02-07T00:00:00Z",
    "advisory" : "RHSA-2023:0629",
    "cpe" : "cpe:/o:redhat:rhel_eus:9.0",
    "package" : "libksba-0:1.5.1-6.el9_0"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform Expansion Pack",
    "release_date" : "2023-02-14T00:00:00Z",
    "advisory" : "RHSA-2023:0756",
    "cpe" : "cpe:/a:redhat:jbosseapxp"
  }, {
    "product_name" : "Red Hat Virtualization 4 for Red Hat Enterprise Linux 8",
    "release_date" : "2023-02-21T00:00:00Z",
    "advisory" : "RHSA-2023:0859",
    "cpe" : "cpe:/o:redhat:rhev_hypervisor:4.4::el8",
    "package" : "redhat-virtualization-host-0:4.5.3-202302150956_8.6"
  } ],
  "package_state" : [ {
    "product_name" : "Red Hat Enterprise Linux 6",
    "fix_state" : "Out of support scope",
    "package_name" : "libksba",
    "cpe" : "cpe:/o:redhat:enterprise_linux:6"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2022-47629\nhttps://nvd.nist.gov/vuln/detail/CVE-2022-47629\nhttps://gnupg.org/blog/20221017-pepe-left-the-ksba.html" ],
  "name" : "CVE-2022-47629",
  "csaw" : false
}