GHSA-c7ph-f7jm-xv4w
rPGP's integrity protection of encrypted data was not always checked
Details
### Summary For some messages, rPGP returned incorrectly decrypted data without signaling that integrity protection was invalid.
### Details When decrypting SEIPD (Symmetrically Encrypted and Integrity Protected Data Packet), rPGP previously did not under all circumstances report the absence of valid integrity protection to callers of the library.
### Impact While the resulting invalid decryption output is not attacker controlled, its contents may be a security concern if an attacker can gain access to it.
### Attribution Discovered internally in the course of rPGP development work.
Are you affected?
Enter the version of the package you're using.
Affected packages
0.16.0-alpha.0Fixed in: 0.19.0Upgrade pgp to 0.19.0 or newer (ecosystem crates.io).