Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-58261

Опубликовано: 27 июл. 2025
Источник: debian
EPSS Низкий

Описание

The sequoia-openpgp crate 1.13.0 before 1.21.0 for Rust allows an infinite loop of "Reading a cert: Invalid operation: Not a Key packet" messages for RawCertParser operations that encounter an unsupported primary key type.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
rust-sequoia-openpgpfixed1.21.0-1package
rust-sequoia-openpgpnot-affectedbookwormpackage
rust-sequoia-openpgpnot-affectedbullseyepackage

Примечания

  • https://rustsec.org/advisories/RUSTSEC-2024-0345.html

  • https://gitlab.com/sequoia-pgp/sequoia/-/issues/1106

  • Fixed by: https://gitlab.com/sequoia-pgp/sequoia/-/commit/81fa1d8440116712365106bca7bd81b46349d9c0 (openpgp/v1.21.0)

EPSS

Процентиль: 2%
0.00013
Низкий

Связанные уязвимости

CVSS3: 2.9
ubuntu
5 месяцев назад

The sequoia-openpgp crate 1.13.0 before 1.21.0 for Rust allows an infinite loop of "Reading a cert: Invalid operation: Not a Key packet" messages for RawCertParser operations that encounter an unsupported primary key type.

CVSS3: 2.9
redhat
5 месяцев назад

The sequoia-openpgp crate 1.13.0 before 1.21.0 for Rust allows an infinite loop of "Reading a cert: Invalid operation: Not a Key packet" messages for RawCertParser operations that encounter an unsupported primary key type.

CVSS3: 2.9
nvd
5 месяцев назад

The sequoia-openpgp crate 1.13.0 before 1.21.0 for Rust allows an infinite loop of "Reading a cert: Invalid operation: Not a Key packet" messages for RawCertParser operations that encounter an unsupported primary key type.

CVSS3: 2.9
github
больше 1 года назад

Low severity (DoS) vulnerability in sequoia-openpgp

EPSS

Процентиль: 2%
0.00013
Низкий