CVE-2024-53857

NameCVE-2024-53857
DescriptionrPGP is a pure Rust implementation of OpenPGP. Prior to 0.14.1, rPGP allows attackers to trigger resource exhaustion vulnerabilities in rpgp by providing crafted messages. This affects general message parsing and decryption with symmetric keys.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
rust-pgp (PTS)sid, trixie0.14.2-2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
rust-pgpsource(unstable)0.14.2-1

Notes

https://github.com/rpgp/rpgp/security/advisories/GHSA-4grw-m28r-q285

Search for package or bug name: Reporting problems