CVE-2024-53856
Publication date 5 December 2024
Last updated 11 December 2024
Ubuntu priority
rPGP is a pure Rust implementation of OpenPGP. Prior to 0.14.1, rPGP allows an attacker to trigger rpgp crashes by providing crafted data. This vulnerability is fixed in 0.14.1.
Status
Package | Ubuntu Release | Status |
---|---|---|
rust-pgp | 24.10 oracular | Not in release |
24.04 LTS noble | Not in release | |
22.04 LTS jammy | Not in release | |
20.04 LTS focal | Not in release | |
18.04 LTS bionic | Not in release | |
16.04 LTS xenial | Not in release | |
14.04 LTS trusty | Not in release |
Notes
rodrigo-zaiden
rust-pgp is coming for Plucky (as of 2024-12-06 it is on proposed), for now it is marked as DNE, but shouldn't retire it yet. it will probably move to not-affected as the version in proposed is 0.14.2-2