CVE-2024-53856CWE-130CWE-148CWE-617

rPGP Panics on Malformed Untrusted Input

High · published December 5, 2024

CVSS v3.1
7.5
EPSS
0%
Percentile
37.5
In the wild
Unconfirmed
What it is

rPGP is a pure Rust implementation of OpenPGP. Prior to 0.14.1, rPGP allows an attacker to trigger rpgp crashes by providing crafted data. This vulnerability is fixed in 0.14.1.

The record
Technical detail
CVSS v3.1
7.5 · HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS v4.0
Not supplied
EPSS
0.00448 · 37.5th percentile
Weaknesses
CWE-130 · Improper Handling of Length Parameter Inconsistency; CWE-148 · Improper Neutralization of Input Leaders; CWE-617 · Reachable Assertion
Published
2024-12-05T15:24Z
EPSS history
Timeline
  • 05 DEC 15:24Z
    rPGP Panics on Malformed Untrusted Input
    cvelistv5