In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade sequoia-openpgp
to version 1.21.0 or higher.
sequoia-openpgp is a This crate aims to provide a complete implementation of OpenPGP as defined by RFC 4880 as well as some extensions (e.g., RFC 6637, which describes ECC cryptography for OpenPGP. This includes support for unbuffered message processing.
Affected versions of this package are vulnerable to Infinite loop due to the RawCertParser
process. An attacker can cause the application to enter an infinite loop by sending unsupported cert versions.