rPGP is a pure Rust implementation of OpenPGP. Prior to 0.14.1, rPGP allows attackers to trigger resource exhaustion vulnerabilities in rpgp by providing crafted messages. This affects general message parsing and decryption with symmetric keys.
Metrics
Affected Vendors & Products
References
History
Fri, 11 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Thu, 05 Dec 2024 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Rpgp
Rpgp rpgp |
|
| CPEs | cpe:2.3:a:rpgp:rpgp:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Rpgp
Rpgp rpgp |
|
| Metrics |
ssvc
|
Thu, 05 Dec 2024 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | rPGP is a pure Rust implementation of OpenPGP. Prior to 0.14.1, rPGP allows attackers to trigger resource exhaustion vulnerabilities in rpgp by providing crafted messages. This affects general message parsing and decryption with symmetric keys. | |
| Title | rPGP Potential Resource Exhaustion when handling Untrusted Messages | |
| Weaknesses | CWE-770 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2024-12-05T15:22:09.049Z
Updated: 2024-12-05T16:34:13.917Z
Reserved: 2024-11-22T17:30:02.142Z
Link: CVE-2024-53857
Updated: 2024-12-05T16:34:05.683Z
Status : Received
Published: 2024-12-05T16:15:26.393
Modified: 2024-12-05T16:15:26.393
Link: CVE-2024-53857
No data.
ReportizFlow