Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-53857

Опубликовано: 05 дек. 2024
Источник: debian

Описание

rPGP is a pure Rust implementation of OpenPGP. Prior to 0.14.1, rPGP allows attackers to trigger resource exhaustion vulnerabilities in rpgp by providing crafted messages. This affects general message parsing and decryption with symmetric keys.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
rust-pgpfixed0.14.2-1package

Примечания

  • https://github.com/rpgp/rpgp/security/advisories/GHSA-4grw-m28r-q285

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 1 года назад

rPGP is a pure Rust implementation of OpenPGP. Prior to 0.14.1, rPGP allows attackers to trigger resource exhaustion vulnerabilities in rpgp by providing crafted messages. This affects general message parsing and decryption with symmetric keys.

CVSS3: 7.5
nvd
около 1 года назад

rPGP is a pure Rust implementation of OpenPGP. Prior to 0.14.1, rPGP allows attackers to trigger resource exhaustion vulnerabilities in rpgp by providing crafted messages. This affects general message parsing and decryption with symmetric keys.

CVSS3: 7.5
github
около 1 года назад

rPGP Potential Resource Exhaustion when handling Untrusted Messages