Описание
An issue was discovered in the serde_cbor crate before 0.10.2 for Rust. The CBOR deserializer can cause stack consumption via nested semantic tags.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| rust-serde-cbor | not-affected | package |
Примечания
https://rustsec.org/advisories/RUSTSEC-2019-0025.html
Связанные уязвимости
CVSS3: 7.5
ubuntu
около 5 лет назад
An issue was discovered in the serde_cbor crate before 0.10.2 for Rust. The CBOR deserializer can cause stack consumption via nested semantic tags.
CVSS3: 7.5
nvd
около 5 лет назад
An issue was discovered in the serde_cbor crate before 0.10.2 for Rust. The CBOR deserializer can cause stack consumption via nested semantic tags.