CVE-2023-53161
Severity CVSS v4.0:
Pending analysis
Type:
CWE-125
Out-of-bounds Read
Publication date:
28/07/2025
Last modified:
06/08/2025
Description
The buffered-reader crate before 1.1.5 for Rust allows out-of-bounds array access and a panic.
Impact
Base Score 3.x
2.90
Severity 3.x
LOW
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:sequoia-pgp:buffered-reader:*:*:*:*:*:rust:*:* | 1.0.2 (excluding) | |
| cpe:2.3:a:sequoia-pgp:buffered-reader:*:*:*:*:*:rust:*:* | 1.1.0 (including) | 1.1.5 (excluding) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://crates.io/crates/buffered-reader
- https://github.com/advisories/GHSA-29mf-62xx-28jq
- https://gitlab.com/sequoia-pgp/sequoia/-/tags/buffered-reader%2Fv1.0.2
- https://gitlab.com/sequoia-pgp/sequoia/-/tags/buffered-reader%2Fv1.1.5
- https://lists.sequoia-pgp.org/hyperkitty/list/announce@lists.sequoia-pgp.org/thread/SN2E3QRT4DMQ5JNEK6VIN6DJ5SH766DI/
- https://rustsec.org/advisories/RUSTSEC-2023-0039.html



