CVE-2024-53856CWE-130CWE-148CWE-617
rPGP Panics on Malformed Untrusted Input
High · published December 5, 2024
What it is
rPGP is a pure Rust implementation of OpenPGP. Prior to 0.14.1, rPGP allows an attacker to trigger rpgp crashes by providing crafted data. This vulnerability is fixed in 0.14.1.
The record
Technical detail
- CVSS v3.1
- 7.5 · HIGH
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- CVSS v4.0
- Not supplied
- EPSS
- 0.00448 · 37.5th percentile
- Weaknesses
- CWE-130 · Improper Handling of Length Parameter Inconsistency; CWE-148 · Improper Neutralization of Input Leaders; CWE-617 · Reachable Assertion
- Published
- 2024-12-05T15:24Z
EPSS history
Timeline