VDB
Sign up
MEDIUM5.3

GHSA-v6x3-9r38-r27q

Sequoia PGP has Subtraction Overflow when aes_key_unwrap function is provided ciphertext that is too short

Details

In Sequoia before 2.1.0, aes_key_unwrap panics if passed a ciphertext that is too short. A remote attacker can take advantage of this issue to crash an application by sending a victim an encrypted message with a crafted PKESK or SKESK packet.

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/sequoia-openpgp
Introduced in: 0Fixed in: 2.1.0

Upgrade sequoia-openpgp to 2.1.0 or newer (ecosystem crates.io).

References