Vulnerabilities > CVE-2022-23951 - Unspecified vulnerability in Keylime
Attack vector
LOCAL Attack complexity
LOW Privileges required
NONE Confidentiality impact
NONE Integrity impact
NONE Availability impact
HIGH Summary
In Keylime before 6.3.0, quote responses from the agent can contain possibly untrusted ZIP data which can lead to zip bombs.
Vulnerable Configurations
References
- https://github.com/keylime/keylime/commit/6e44758b64b0ee13564fc46e807f4ba98091c355
- https://github.com/keylime/keylime/commit/6e44758b64b0ee13564fc46e807f4ba98091c355
- https://github.com/keylime/keylime/security/advisories/GHSA-6xx7-m45w-76m2
- https://github.com/keylime/keylime/security/advisories/GHSA-6xx7-m45w-76m2
- https://seclists.org/oss-sec/2022/q1/101
- https://seclists.org/oss-sec/2022/q1/101