Vulnerability Description
The sequoia-openpgp crate before 1.16.0 for Rust allows out-of-bounds array access and a panic.
CVSS Score
2.9
LOW
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sequoia-Pgp | Sequoia-Openpgp | < 1.1.1 |
Related Weaknesses (CWE)
References
- https://crates.io/crates/sequoia-openpgpProduct
- https://github.com/advisories/GHSA-25mx-8f3v-8wh7Third Party Advisory
- https://lists.sequoia-pgp.org/hyperkitty/list/[email protected]/thrPatch
- https://rustsec.org/advisories/RUSTSEC-2023-0038.htmlThird Party Advisory
FAQ
What is CVE-2023-53160?
CVE-2023-53160 is a vulnerability with a CVSS score of 2.9 (LOW). The sequoia-openpgp crate before 1.16.0 for Rust allows out-of-bounds array access and a panic.
How severe is CVE-2023-53160?
CVE-2023-53160 has been rated LOW with a CVSS base score of 2.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-53160?
Check the references section above for vendor advisories and patch information. Affected products include: Sequoia-Pgp Sequoia-Openpgp.