CVE-2024-53857

CVSS V2 None CVSS V3 None
Description
rPGP is a pure Rust implementation of OpenPGP. Prior to 0.14.1, rPGP allows attackers to trigger resource exhaustion vulnerabilities in rpgp by providing crafted messages. This affects general message parsing and decryption with symmetric keys.
Overview
  • CVE ID
  • CVE-2024-53857
  • Assigner
  • GitHub_M
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2024-12-05T15:22:09.049Z
  • Last Modified Date
  • 2024-12-05T16:34:13.917Z
References
Reference URL Reference Tags
https://github.com/rpgp/rpgp/security/advisories/GHSA-4grw-m28r-q285 x_refsource_CONFIRM
History
Created Old Value New Value Data Type Notes
2024-12-06 13:32:09 Added to TrackCVE