Debian Rnp vulnerabilities
4 known vulnerabilities affecting debian/rnp.
Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH2MEDIUM1LOW1
Vulnerabilities
Page 1 of 1
CVE-2025-13470LOWCVSS 7.7fixed in rnp 0.18.1-1 (forky)2025
CVE-2025-13470 [HIGH] CVE-2025-13470: rnp - In RNP version 0.18.0 a refactoring regression causes the symmetric session key...
In RNP version 0.18.0 a refactoring regression causes the symmetric session key used for Public-Key Encrypted Session Key (PKESK) packets to be left uninitialized except for zeroing, resulting in it always being an all-zero byte array. Any data encrypted using public-key encryption in this release can be decrypted trivially by supplying an all-zero session key, fully co
debian
CVE-2023-29480HIGHCVSS 7.5fixed in rnp 0.16.3-1 (bookworm)2023
CVE-2023-29480 [HIGH] CVE-2023-29480: rnp - Ribose RNP before 0.16.3 sometimes lets secret keys remain unlocked after use.
Ribose RNP before 0.16.3 sometimes lets secret keys remain unlocked after use.
Scope: local
bookworm: resolved (fixed in 0.16.3-1)
forky: resolved (fixed in 0.16.3-1)
sid: resolved (fixed in 0.16.3-1)
trixie: resolved (fixed in 0.16.3-1)
debian
CVE-2023-29479MEDIUMCVSS 5.3fixed in rnp 0.16.3-1 (bookworm)2023
CVE-2023-29479 [MEDIUM] CVE-2023-29479: rnp - Ribose RNP before 0.16.3 may hang when the input is malformed.
Ribose RNP before 0.16.3 may hang when the input is malformed.
Scope: local
bookworm: resolved (fixed in 0.16.3-1)
forky: resolved (fixed in 0.16.3-1)
sid: resolved (fixed in 0.16.3-1)
trixie: resolved (fixed in 0.16.3-1)
debian
CVE-2021-33589HIGHCVSS 7.5fixed in rnp 0.15.1-1 (bookworm)2021
CVE-2021-33589 [HIGH] CVE-2021-33589: rnp - Ribose RNP before 0.15.1 does not implement a required step in a cryptographic a...
Ribose RNP before 0.15.1 does not implement a required step in a cryptographic algorithm, resulting in weaker encryption than on the tin of the algorithm.
Scope: local
bookworm: resolved (fixed in 0.15.1-1)
forky: resolved (fixed in 0.15.1-1)
sid: resolved (fixed in 0.15.1-1)
trixie: resolved (fixed in 0.15.1-1)
debian