sequoia-pgp/sequoia

sequoia-pgp/sequoia

Releases111
Frequency3 weeks 3 days
Last Release
Stars472

CVE History

CVEPublishedCVSS v3CVSS v2
5.3 MEDIUM

In Sequoia before 2.1.0, aes_key_unwrap panics if passed a ciphertext that is too short. A remote attacker can take advantage of this issue to crash an application by sending a victim an encrypted message with a crafted PKESK or SKESK packet.

2.9 LOW

The buffered-reader crate before 1.1.5 for Rust allows out-of-bounds array access and a panic.

2.9 LOW

The sequoia-openpgp crate 1.13.0 before 1.21.0 for Rust allows an infinite loop of "Reading a cert: Invalid operation: Not a Key packet" messages for RawCertParser operations that encounter an unsupported primary key type.