Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-53605

Опубликовано: 05 июл. 2025
Источник: debian
EPSS Низкий

Описание

The protobuf crate before 3.7.2 for Rust allows uncontrolled recursion in the protobuf::coded_input_stream::CodedInputStream::skip_group parsing of unknown fields in untrusted input.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
rust-protobuffixed3.7.2-1package
rust-protobufno-dsabookwormpackage

Примечания

  • https://rustsec.org/advisories/RUSTSEC-2024-0437.html

  • https://github.com/stepancheg/rust-protobuf/issues/749

EPSS

Процентиль: 27%
0.00094
Низкий

Связанные уязвимости

CVSS3: 5.9
ubuntu
4 месяца назад

The protobuf crate before 3.7.2 for Rust allows uncontrolled recursion in the protobuf::coded_input_stream::CodedInputStream::skip_group parsing of unknown fields in untrusted input.

CVSS3: 5.9
redhat
4 месяца назад

The protobuf crate before 3.7.2 for Rust allows uncontrolled recursion in the protobuf::coded_input_stream::CodedInputStream::skip_group parsing of unknown fields in untrusted input.

CVSS3: 5.9
nvd
4 месяца назад

The protobuf crate before 3.7.2 for Rust allows uncontrolled recursion in the protobuf::coded_input_stream::CodedInputStream::skip_group parsing of unknown fields in untrusted input.

CVSS3: 5.9
msrc
2 месяца назад

The protobuf crate before 3.7.2 for Rust allows uncontrolled recursion in the protobuf::coded_input_stream::CodedInputStream::skip_group parsing of unknown fields in untrusted input.

github
8 месяцев назад

Crash due to uncontrolled recursion in protobuf crate

EPSS

Процентиль: 27%
0.00094
Низкий