Infinite loop Affecting sequoia-openpgp package, versions >=1.13.0 <1.21.0


Severity

Recommended
0.0
high
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-RUST-SEQUOIAOPENPGP-7411204
  • published27 Jun 2024
  • disclosed26 Jun 2024
  • creditUnknown

Introduced: 26 Jun 2024

CVE NOT AVAILABLE CWE-835  (opens in a new tab)

How to fix?

Upgrade sequoia-openpgp to version 1.21.0 or higher.

Overview

sequoia-openpgp is a This crate aims to provide a complete implementation of OpenPGP as defined by RFC 4880 as well as some extensions (e.g., RFC 6637, which describes ECC cryptography for OpenPGP. This includes support for unbuffered message processing.

Affected versions of this package are vulnerable to Infinite loop due to the RawCertParser process. An attacker can cause the application to enter an infinite loop by sending unsupported cert versions.

CVSS Scores

version 4.0
version 3.1