Описание
A flaw was found in Rustls 0.23.13 and related APIs. This vulnerability allows denial of service (panic) via a fragmented TLS ClientHello message.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| rust-rustls | not-affected | package |
Примечания
https://rustsec.org/advisories/RUSTSEC-2024-0399.html
https://github.com/rustls/rustls/issues/2227
EPSS
Процентиль: 44%
0.0022
Низкий
Связанные уязвимости
CVSS3: 5.3
ubuntu
около 1 года назад
A flaw was found in Rustls 0.23.13 and related APIs. This vulnerability allows denial of service (panic) via a fragmented TLS ClientHello message.
CVSS3: 5.3
redhat
около 1 года назад
A flaw was found in Rustls 0.23.13 and related APIs. This vulnerability allows denial of service (panic) via a fragmented TLS ClientHello message.
CVSS3: 5.3
nvd
около 1 года назад
A flaw was found in Rustls 0.23.13 and related APIs. This vulnerability allows denial of service (panic) via a fragmented TLS ClientHello message.
CVSS3: 5.3
msrc
5 месяцев назад
Rustls: rustls network-reachable panic in `acceptor::accept`
EPSS
Процентиль: 44%
0.0022
Низкий