Vulnerability Details CVE-2024-58261
The sequoia-openpgp crate 1.13.0 before 1.21.0 for Rust allows an infinite loop of "Reading a cert: Invalid operation: Not a Key packet" messages for RawCertParser operations that encounter an unsupported primary key type.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 12.2%
CVSS Severity
CVSS v3 Score 2.9
Products affected by CVE-2024-58261
-
cpe:2.3:a:sequoia-pgp:sequoia-openpgp:1.13.0
-
cpe:2.3:a:sequoia-pgp:sequoia-openpgp:1.14.0
-
cpe:2.3:a:sequoia-pgp:sequoia-openpgp:1.15.0
-
cpe:2.3:a:sequoia-pgp:sequoia-openpgp:1.16.0
-
cpe:2.3:a:sequoia-pgp:sequoia-openpgp:1.16.1
-
cpe:2.3:a:sequoia-pgp:sequoia-openpgp:1.17.0
-
cpe:2.3:a:sequoia-pgp:sequoia-openpgp:1.18.0
-
cpe:2.3:a:sequoia-pgp:sequoia-openpgp:1.19.0
-
cpe:2.3:a:sequoia-pgp:sequoia-openpgp:1.20.0