Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-67897

Опубликовано: 14 дек. 2025
Источник: debian
EPSS Низкий

Описание

In Sequoia before 2.1.0, aes_key_unwrap panics if passed a ciphertext that is too short. A remote attacker can take advantage of this issue to crash an application by sending a victim an encrypted message with a crafted PKESK or SKESK packet.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
rust-sequoia-openpgpfixed2.1.0-1package
rust-sequoia-openpgpfixed2.0.0-2+deb13u1trixiepackage
rust-sequoia-openpgpno-dsabookwormpackage
rust-sequoia-openpgpignoredbullseyepackage

Примечания

  • Fixed by: https://gitlab.com/sequoia-pgp/sequoia/-/commit/b59886e5e7bdf7169ed330f309a6633d131776e5 (openpgp/v2.1.0)

EPSS

Процентиль: 41%
0.00195
Низкий

Связанные уязвимости

CVSS3: 5.3
ubuntu
4 месяца назад

In Sequoia before 2.1.0, aes_key_unwrap panics if passed a ciphertext that is too short. A remote attacker can take advantage of this issue to crash an application by sending a victim an encrypted message with a crafted PKESK or SKESK packet.

CVSS3: 5.3
redhat
4 месяца назад

In Sequoia before 2.1.0, aes_key_unwrap panics if passed a ciphertext that is too short. A remote attacker can take advantage of this issue to crash an application by sending a victim an encrypted message with a crafted PKESK or SKESK packet.

CVSS3: 5.3
nvd
4 месяца назад

In Sequoia before 2.1.0, aes_key_unwrap panics if passed a ciphertext that is too short. A remote attacker can take advantage of this issue to crash an application by sending a victim an encrypted message with a crafted PKESK or SKESK packet.

msrc
3 месяца назад

In Sequoia before 2.1.0, aes_key_unwrap panics if passed a ciphertext that is too short. A remote attacker can take advantage of this issue to crash an application by sending a victim an encrypted message with a crafted PKESK or SKESK packet.

CVSS3: 5.3
github
4 месяца назад

Sequoia PGP has Subtraction Overflow when aes_key_unwrap function is provided ciphertext that is too short

EPSS

Процентиль: 41%
0.00195
Низкий