CVE-2022-23951

In Keylime before 6.3.0, quote responses from the agent can contain possibly untrusted ZIP data which can lead to zip bombs.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.5 MEDIUM
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 20%
Affected Products (NVD)
VendorProductVersion
keylimekeylime
𝑥
< 6.3.0
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
keylime
bionic
dne
focal
dne
jammy
dne
trusty
dne
xenial
dne
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
keylime-agent
suse enterprise desktop 15 SP4
6.3.0-150400.2.5
fixed
suse enterprise desktop 15 SP5
6.3.2-150400.4.14.1
fixed
suse enterprise desktop 15 SP6
6.3.2-150400.4.20.1
fixed
suse enterprise desktop 15 SP7
6.3.2-150400.4.20.1
fixed
suse enterprise sap 15 SP4
6.3.0-150400.2.5
fixed
suse enterprise sap 15 SP5
6.3.2-150400.4.14.1
fixed
suse enterprise sap 15 SP6
6.3.2-150400.4.20.1
fixed
suse enterprise sap 15 SP7
6.3.2-150400.4.20.1
fixed
suse enterprise server 15 SP4
6.3.0-150400.2.5
fixed
suse enterprise server 15 SP5
6.3.2-150400.4.14.1
fixed
suse enterprise server 15 SP6
6.3.2-150400.4.20.1
fixed
suse enterprise server 15 SP7
6.3.2-150400.4.20.1
fixed
keylime-config
suse enterprise desktop 15 SP4
6.3.0-150400.2.5
fixed
suse enterprise desktop 15 SP5
6.3.2-150400.4.14.1
fixed
suse enterprise desktop 15 SP6
6.3.2-150400.4.20.1
fixed
suse enterprise desktop 15 SP7
6.3.2-150400.4.20.1
fixed
suse enterprise sap 15 SP4
6.3.0-150400.2.5
fixed
suse enterprise sap 15 SP5
6.3.2-150400.4.14.1
fixed
suse enterprise sap 15 SP6
6.3.2-150400.4.20.1
fixed
suse enterprise sap 15 SP7
6.3.2-150400.4.20.1
fixed
suse enterprise server 15 SP4
6.3.0-150400.2.5
fixed
suse enterprise server 15 SP5
6.3.2-150400.4.14.1
fixed
suse enterprise server 15 SP6
6.3.2-150400.4.20.1
fixed
suse enterprise server 15 SP7
6.3.2-150400.4.20.1
fixed
keylime-firewalld
suse enterprise desktop 15 SP4
6.3.0-150400.2.5
fixed
suse enterprise desktop 15 SP5
6.3.2-150400.4.14.1
fixed
suse enterprise desktop 15 SP6
6.3.2-150400.4.20.1
fixed
suse enterprise desktop 15 SP7
6.3.2-150400.4.20.1
fixed
suse enterprise sap 15 SP4
6.3.0-150400.2.5
fixed
suse enterprise sap 15 SP5
6.3.2-150400.4.14.1
fixed
suse enterprise sap 15 SP6
6.3.2-150400.4.20.1
fixed
suse enterprise sap 15 SP7
6.3.2-150400.4.20.1
fixed
suse enterprise server 15 SP4
6.3.0-150400.2.5
fixed
suse enterprise server 15 SP5
6.3.2-150400.4.14.1
fixed
suse enterprise server 15 SP6
6.3.2-150400.4.20.1
fixed
suse enterprise server 15 SP7
6.3.2-150400.4.20.1
fixed
keylime-logrotate
suse enterprise desktop 15 SP5
6.3.2-150400.4.14.1
fixed
suse enterprise desktop 15 SP6
6.3.2-150400.4.20.1
fixed
suse enterprise desktop 15 SP7
6.3.2-150400.4.20.1
fixed
suse enterprise sap 15 SP5
6.3.2-150400.4.14.1
fixed
suse enterprise sap 15 SP6
6.3.2-150400.4.20.1
fixed
suse enterprise sap 15 SP7
6.3.2-150400.4.20.1
fixed
suse enterprise server 15 SP5
6.3.2-150400.4.14.1
fixed
suse enterprise server 15 SP6
6.3.2-150400.4.20.1
fixed
suse enterprise server 15 SP7
6.3.2-150400.4.20.1
fixed
keylime-registrar
suse enterprise desktop 15 SP4
6.3.0-150400.2.5
fixed
suse enterprise desktop 15 SP5
6.3.2-150400.4.14.1
fixed
suse enterprise desktop 15 SP6
6.3.2-150400.4.20.1
fixed
suse enterprise desktop 15 SP7
6.3.2-150400.4.20.1
fixed
suse enterprise sap 15 SP4
6.3.0-150400.2.5
fixed
suse enterprise sap 15 SP5
6.3.2-150400.4.14.1
fixed
suse enterprise sap 15 SP6
6.3.2-150400.4.20.1
fixed
suse enterprise sap 15 SP7
6.3.2-150400.4.20.1
fixed
suse enterprise server 15 SP4
6.3.0-150400.2.5
fixed
suse enterprise server 15 SP5
6.3.2-150400.4.14.1
fixed
suse enterprise server 15 SP6
6.3.2-150400.4.20.1
fixed
suse enterprise server 15 SP7
6.3.2-150400.4.20.1
fixed
keylime-tpm_cert_store
suse enterprise desktop 15 SP4
6.3.0-150400.2.5
fixed
suse enterprise desktop 15 SP5
6.3.2-150400.4.14.1
fixed
suse enterprise desktop 15 SP6
6.3.2-150400.4.20.1
fixed
suse enterprise desktop 15 SP7
6.3.2-150400.4.20.1
fixed
suse enterprise sap 15 SP4
6.3.0-150400.2.5
fixed
suse enterprise sap 15 SP5
6.3.2-150400.4.14.1
fixed
suse enterprise sap 15 SP6
6.3.2-150400.4.20.1
fixed
suse enterprise sap 15 SP7
6.3.2-150400.4.20.1
fixed
suse enterprise server 15 SP4
6.3.0-150400.2.5
fixed
suse enterprise server 15 SP5
6.3.2-150400.4.14.1
fixed
suse enterprise server 15 SP6
6.3.2-150400.4.20.1
fixed
suse enterprise server 15 SP7
6.3.2-150400.4.20.1
fixed
keylime-verifier
suse enterprise desktop 15 SP4
6.3.0-150400.2.5
fixed
suse enterprise desktop 15 SP5
6.3.2-150400.4.14.1
fixed
suse enterprise desktop 15 SP6
6.3.2-150400.4.20.1
fixed
suse enterprise desktop 15 SP7
6.3.2-150400.4.20.1
fixed
suse enterprise sap 15 SP4
6.3.0-150400.2.5
fixed
suse enterprise sap 15 SP5
6.3.2-150400.4.14.1
fixed
suse enterprise sap 15 SP6
6.3.2-150400.4.20.1
fixed
suse enterprise sap 15 SP7
6.3.2-150400.4.20.1
fixed
suse enterprise server 15 SP4
6.3.0-150400.2.5
fixed
suse enterprise server 15 SP5
6.3.2-150400.4.14.1
fixed
suse enterprise server 15 SP6
6.3.2-150400.4.20.1
fixed
suse enterprise server 15 SP7
6.3.2-150400.4.20.1
fixed
python3-keylime
suse enterprise desktop 15 SP4
6.3.0-150400.2.5
fixed
suse enterprise desktop 15 SP5
6.3.2-150400.4.14.1
fixed
suse enterprise desktop 15 SP6
6.3.2-150400.4.20.1
fixed
suse enterprise desktop 15 SP7
6.3.2-150400.4.20.1
fixed
suse enterprise sap 15 SP4
6.3.0-150400.2.5
fixed
suse enterprise sap 15 SP5
6.3.2-150400.4.14.1
fixed
suse enterprise sap 15 SP6
6.3.2-150400.4.20.1
fixed
suse enterprise sap 15 SP7
6.3.2-150400.4.20.1
fixed
suse enterprise server 15 SP4
6.3.0-150400.2.5
fixed
suse enterprise server 15 SP5
6.3.2-150400.4.14.1
fixed
suse enterprise server 15 SP6
6.3.2-150400.4.20.1
fixed
suse enterprise server 15 SP7
6.3.2-150400.4.20.1
fixed