Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-29922

Опубликовано: 07 авг. 2021
Источник: debian
EPSS Низкий

Описание

library/std/src/net/parser.rs in Rust before 1.53.0 does not properly consider extraneous zero characters at the beginning of an IP address string, which (in some situations) allows attackers to bypass access control that is based on IP addresses, because of unexpected octal interpretation.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
rustcfixed1.53.0+dfsg1-1package
rustcno-dsabullseyepackage
rustcno-dsabusterpackage
rustcignoredstretchpackage

Примечания

  • https://github.com/rust-lang/rust/issues/83648

  • https://github.com/rust-lang/rust/pull/83652

  • https://github.com/sickcodes/security/blob/master/advisories/SICK-2021-015.md

  • https://github.com/rust-lang/rust/commit/974192cd98b3efca8e5cd293f641f561e7487b30

EPSS

Процентиль: 39%
0.00175
Низкий

Связанные уязвимости

CVSS3: 9.1
ubuntu
больше 4 лет назад

library/std/src/net/parser.rs in Rust before 1.53.0 does not properly consider extraneous zero characters at the beginning of an IP address string, which (in some situations) allows attackers to bypass access control that is based on IP addresses, because of unexpected octal interpretation.

CVSS3: 7.3
redhat
больше 4 лет назад

library/std/src/net/parser.rs in Rust before 1.53.0 does not properly consider extraneous zero characters at the beginning of an IP address string, which (in some situations) allows attackers to bypass access control that is based on IP addresses, because of unexpected octal interpretation.

CVSS3: 9.1
nvd
больше 4 лет назад

library/std/src/net/parser.rs in Rust before 1.53.0 does not properly consider extraneous zero characters at the beginning of an IP address string, which (in some situations) allows attackers to bypass access control that is based on IP addresses, because of unexpected octal interpretation.

rocky
около 4 лет назад

Moderate: rust-toolset:rhel8 security, bug fix, and enhancement update

CVSS3: 9.1
github
больше 3 лет назад

library/std/src/net/parser.rs in Rust before 1.53.0 does not properly consider extraneous zero characters at the beginning of an IP address string, which (in some situations) allows attackers to bypass access control that is based on IP addresses, because of unexpected octal interpretation.

EPSS

Процентиль: 39%
0.00175
Низкий