CVE-2023-53160Out-of-bounds Read in Sequoia

CWE-125Out-of-bounds Read7 documents5 sources
Severity
5.3MEDIUMNVD
EPSS
0.1%
top 80.47%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 28

Description

The sequoia-openpgp crate before 1.16.0 for Rust allows out-of-bounds array access and a panic.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:LExploitability: 3.9 | Impact: 1.4

Affected Packages4 packages

debiandebian/rust-sequoia-openpgp< rust-sequoia-openpgp 1.16.0-1 (forky)
NVDsequoia-pgp/sequoia-openpgp1.2.01.8.1+2
crates.iosequoia-pgp/sequoia-openpgp1.2.01.8.1+3
CVEListV5sequoia-pgp/sequoia1.2.01.8.1+2

Patches

🔴Vulnerability Details

4
OSV
CVE-2023-53160: The sequoia-openpgp crate before 12025-07-28
OSV
sequoia-openpgp vulnerable to out-of-bounds array access leading to panic2023-06-06
GHSA
sequoia-openpgp vulnerable to out-of-bounds array access leading to panic2023-06-06
OSV
Out-of-bounds array access leads to panic2023-05-16

📋Vendor Advisories

2
Red Hat
sequoia-openpgp: Sequoia OpenPGP Array Access Panic2025-07-28
Debian
CVE-2023-53160: rust-sequoia-openpgp - The sequoia-openpgp crate before 1.16.0 for Rust allows out-of-bounds array acce...2023