libksba: parsing failure
Posted Oct 19, 2006 8:24 UTC (Thu) by dd9jn
Parent article: libksba: parsing failure
As author of libksba (clearly stated with a security address in AUTHORS), I have not been contacted. Ubuntu seems to have fixed this in a version 0.9.9 whereas other distributions talk about 0.9.15 not affected but anyway fixed! Others even claim that 1.0 is affected.
According to my records the last such bug has been fixed with 0.9.10 back in December 2004. So the Ubuntu fix looks plausible.
However, I have no idea whether this is actually what the CVE talks about.
Looking at the Suse update, they include a patch for 0.9.12 which fixes a parsing problem with some certificates as well as a one liner to fix a possible NULL dereference. That fix definitely does not fix any exploitable bug as indicated in the CVE. According to their changelog it fixes bug 177462. I have found no way to access the Suse bug tracker to look it up.
Issuing a CVE candidate without contacting the author is IMHO somewhat unprofessional. Is there still something lurking in 1.0.0?
to post comments)