rPGP is a pure Rust implementation of OpenPGP. Prior to 0.14.1, rPGP allows attackers to trigger resource exhaustion vulnerabilities in rpgp by providing crafted messages. This affects general message parsing and decryption with symmetric keys.
History

Thu, 05 Dec 2024 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Rpgp
Rpgp rpgp
CPEs cpe:2.3:a:rpgp:rpgp:*:*:*:*:*:*:*:*
Vendors & Products Rpgp
Rpgp rpgp
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 05 Dec 2024 15:45:00 +0000

Type Values Removed Values Added
Description rPGP is a pure Rust implementation of OpenPGP. Prior to 0.14.1, rPGP allows attackers to trigger resource exhaustion vulnerabilities in rpgp by providing crafted messages. This affects general message parsing and decryption with symmetric keys.
Title rPGP Potential Resource Exhaustion when handling Untrusted Messages
Weaknesses CWE-770
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2024-12-05T15:22:09.049Z

Updated: 2024-12-05T16:34:13.917Z

Reserved: 2024-11-22T17:30:02.142Z

Link: CVE-2024-53857

cve-icon Vulnrichment

Updated: 2024-12-05T16:34:05.683Z

cve-icon NVD

Status : Received

Published: 2024-12-05T16:15:26.393

Modified: 2024-12-05T16:15:26.393

Link: CVE-2024-53857

cve-icon Redhat

No data.