CVE Vulnerabilities

CVE-2022-23951

Published: Sep 21, 2022 | Modified: Dec 21, 2022
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

In Keylime before 6.3.0, quote responses from the agent can contain possibly untrusted ZIP data which can lead to zip bombs.

Affected Software

Name Vendor Start Version End Version
Keylime Keylime * 6.3.0 (excluding)

References