5
CVSSv2

CVE-2006-5111

Published: 03/10/2006 Updated: 20/07/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

The libksba library 0.9.12 and possibly other versions, as used by gpgsm in the newpg package on SUSE LINUX, allows malicious users to cause a denial of service (application crash) via a malformed X.509 certificate in a signature.

Vulnerable Product Search on Vulmon Subscribe to Product

libksba library libksba library 0.9.12

Vendor Advisories

Debian Bug report logs - #391278 CVE-2006-5111: libksba denial of service (application crash) vulnerability Package: libksba8; Maintainer for libksba8 is Debian GnuTLS Maintainers <pkg-gnutls-maint@listsaliothdebianorg>; Source for libksba8 is src:libksba (PTS, buildd, popcon) Reported by: Stefan Fritsch <sf@sfritschd ...
A parsing failure was discovered in the handling of X509 certificates that contained extra trailing data Malformed or malicious certificates could cause services using libksba to crash, potentially creating a denial of service ...