The sequoia-openpgp crate before 1.16.0 for Rust allows out-of-bounds array access and a panic.
{
"binaries": [
{
"binary_name": "librust-sequoia-openpgp+bzip2-dev",
"binary_version": "1.7.0-6"
},
{
"binary_name": "librust-sequoia-openpgp+compression-bzip2-dev",
"binary_version": "1.7.0-6"
},
{
"binary_name": "librust-sequoia-openpgp+compression-deflate-dev",
"binary_version": "1.7.0-6"
},
{
"binary_name": "librust-sequoia-openpgp+compression-dev",
"binary_version": "1.7.0-6"
},
{
"binary_name": "librust-sequoia-openpgp+default-dev",
"binary_version": "1.7.0-6"
},
{
"binary_name": "librust-sequoia-openpgp+flate2-dev",
"binary_version": "1.7.0-6"
},
{
"binary_name": "librust-sequoia-openpgp+nettle-dev",
"binary_version": "1.7.0-6"
},
{
"binary_name": "librust-sequoia-openpgp-dev",
"binary_version": "1.7.0-6"
}
]
}