VYPR

rpm package

opensuse/keybase-client&distro=openSUSE Tumbleweed

pkg:rpm/opensuse/keybase-client&distro=openSUSE%20Tumbleweed

Vulnerabilities (5)

  • CVE-2026-56855HigSep 2, 2026
    affected < 6.6.3-4.1fixed 6.6.3-4.1

    Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and t

  • CVE-2026-46604HigJun 26, 2026
    affected < 6.6.3-2.1fixed 6.6.3-2.1

    The TIFF decoder can panic when decoding an invalid image with an out-of-bounds strip offset.

  • CVE-2026-39824LowMay 22, 2026
    affected < 6.6.3-3.1fixed 6.6.3-3.1

    NewNTUnicodeString does not check for string length overflow. When provided with a string that overflows the maximum size of a NTUnicodeString (a 16-bit number of bytes), it returns a truncated string rather than an error.

  • CVE-2024-24792HigJun 27, 2024
    affected < 6.3.1-2.1fixed 6.3.1-2.1

    Parsing a corrupt or malicious image with invalid color indices can cause a panic.

  • CVE-2023-29408MedAug 2, 2023
    affected < 6.2.2-2.1fixed 6.2.2-2.1

    The TIFF decoder does not place a limit on the size of compressed tile data. A maliciously-crafted image can exploit this to cause a small image (both in terms of pixel width/height, and encoded size) to make the decoder decode large amounts of compressed data, consuming excessiv