Debian Rust-Sequoia-Openpgp vulnerabilities

3 known vulnerabilities affecting debian/rust-sequoia-openpgp.

Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
MEDIUM1LOW2

Vulnerabilities

Page 1 of 1
CVE-2025-67897MEDIUMCVSS 5.3fixed in rust-sequoia-openpgp 2.1.0-1 (forky)2025
CVE-2025-67897 [MEDIUM] CVE-2025-67897: rust-sequoia-openpgp - In Sequoia before 2.1.0, aes_key_unwrap panics if passed a ciphertext that is to... In Sequoia before 2.1.0, aes_key_unwrap panics if passed a ciphertext that is too short. A remote attacker can take advantage of this issue to crash an application by sending a victim an encrypted message with a crafted PKESK or SKESK packet. Scope: local bookworm: open bullseye: open forky: resolved (fixed in 2.1.0-1) sid: resolved (fixed in 2.1.0-1)
debian
CVE-2024-58261LOWCVSS 2.9fixed in rust-sequoia-openpgp 1.21.0-1 (forky)2024
CVE-2024-58261 [LOW] CVE-2024-58261: rust-sequoia-openpgp - The sequoia-openpgp crate 1.13.0 before 1.21.0 for Rust allows an infinite loop ... The sequoia-openpgp crate 1.13.0 before 1.21.0 for Rust allows an infinite loop of "Reading a cert: Invalid operation: Not a Key packet" messages for RawCertParser operations that encounter an unsupported primary key type. Scope: local bookworm: resolved bullseye: resolved forky: resolved (fixed in 1.21.0-1) sid: resolved (fixed in 1.21.0-1) trixie: reso
debian
CVE-2023-53160LOWCVSS 2.9fixed in rust-sequoia-openpgp 1.16.0-1 (forky)2023
CVE-2023-53160 [LOW] CVE-2023-53160: rust-sequoia-openpgp - The sequoia-openpgp crate before 1.16.0 for Rust allows out-of-bounds array acce... The sequoia-openpgp crate before 1.16.0 for Rust allows out-of-bounds array access and a panic. Scope: local bookworm: open bullseye: open forky: resolved (fixed in 1.16.0-1) sid: resolved (fixed in 1.16.0-1) trixie: resolved (fixed in 1.16.0-1)
debian