QID 996204
Date Published: 2023-12-13
QID 996204: Rust (Rust) Security Update for aes-gcm (GHSA-423w-p2w9-r7vq)
In the AES GCM implementation of decrypt_in_place_detached, the decrypted ciphertext (i.e. the correct plaintext) is exposed even if tag verification fails.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-423w-p2w9-r7vq for updates and patch information.
Vendor References
- GHSA-423w-p2w9-r7vq -
github.com/advisories/GHSA-423w-p2w9-r7vq
CVEs related to QID 996204
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-423w-p2w9-r7vq | aes-gcm |
|