VDB
Sign up
MEDIUM

GHSA-c7ph-f7jm-xv4w

rPGP's integrity protection of encrypted data was not always checked

Details

### Summary For some messages, rPGP returned incorrectly decrypted data without signaling that integrity protection was invalid.

### Details When decrypting SEIPD (Symmetrically Encrypted and Integrity Protected Data Packet), rPGP previously did not under all circumstances report the absence of valid integrity protection to callers of the library.

### Impact While the resulting invalid decryption output is not attacker controlled, its contents may be a security concern if an attacker can gain access to it.

### Attribution Discovered internally in the course of rPGP development work.

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/pgp
Introduced in: 0.16.0-alpha.0Fixed in: 0.19.0

Upgrade pgp to 0.19.0 or newer (ecosystem crates.io).

References