The sequoia-openpgp crate before 1.16.0 for Rust allows out-of-bounds array access and a panic.
The product reads data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://crates.io/crates/sequoia-openpgp | product |
https://rustsec.org/advisories/RUSTSEC-2023-0038.html | third party advisory |
https://github.com/advisories/GHSA-25mx-8f3v-8wh7 | third party advisory |
https://lists.sequoia-pgp.org/hyperkitty/list/announce@lists.sequoia-pgp.org/thread/SN2E3QRT4DMQ5JNEK6VIN6DJ5SH766DI/ | patch |