CVE-2024-53856
HIGHrPGP <0.14.1 - Use After Free
Title source: llmDescription
rPGP is a pure Rust implementation of OpenPGP. Prior to 0.14.1, rPGP allows an attacker to trigger rpgp crashes by providing crafted data. This vulnerability is fixed in 0.14.1.
Scores
CVSS v3
7.5
EPSS
0.0028
EPSS Percentile
50.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Classification
CWE
CWE-148
CWE-130
CWE-617
Status
draft
Affected Products (1)
crates.io/pgp
< 0.14.1crates.io
Timeline
Published
Dec 05, 2024
Tracked Since
Feb 18, 2026