sequoia-pgp/sequoia
Releases111
Frequency3 weeks 3 days
Last Release
Stars472
CVE History
| CVE | Published | CVSS v3 | CVSS v2 |
|---|---|---|---|
| 5.3 MEDIUM | — | ||
In Sequoia before 2.1.0, aes_key_unwrap panics if passed a ciphertext that is too short. A remote attacker can take advantage of this issue to crash an application by sending a victim an encrypted message with a crafted PKESK or SKESK packet. | |||
| 2.9 LOW | — | ||
The buffered-reader crate before 1.1.5 for Rust allows out-of-bounds array access and a panic. | |||
| 2.9 LOW | — | ||
The sequoia-openpgp crate 1.13.0 before 1.21.0 for Rust allows an infinite loop of "Reading a cert: Invalid operation: Not a Key packet" messages for RawCertParser operations that encounter an unsupported primary key type. | |||