Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-29mf-62xx-28jq

Опубликовано: 06 июн. 2023
Источник: github
Github: Прошло ревью
CVSS3: 2.9

Описание

buffered-reader vulnerable to out-of-bounds array access leading to panic

Affected versions of the crate have a bug where attacker-controlled input can result in the use of an out-of-bound array index. Rust detects the use of the out-of-bound index and causes the application to panic. An attacker may be able to use this to cause a denial-of-service. However, it is not possible for an attacker to read from or write to the application's address space.

Пакеты

Наименование

buffered-reader

rust
Затронутые версииВерсия исправления

< 1.0.2

1.0.2

Наименование

buffered-reader

rust
Затронутые версииВерсия исправления

>= 1.1.0, < 1.1.5

1.1.5

EPSS

Процентиль: 9%
0.00035
Низкий

2.9 Low

CVSS3

Связанные уязвимости

CVSS3: 2.9
ubuntu
23 дня назад

The buffered-reader crate before 1.1.5 for Rust allows out-of-bounds array access and a panic.

CVSS3: 3.3
redhat
23 дня назад

The buffered-reader crate before 1.1.5 for Rust allows out-of-bounds array access and a panic.

CVSS3: 2.9
nvd
23 дня назад

The buffered-reader crate before 1.1.5 for Rust allows out-of-bounds array access and a panic.

CVSS3: 2.9
debian
23 дня назад

The buffered-reader crate before 1.1.5 for Rust allows out-of-bounds a ...

EPSS

Процентиль: 9%
0.00035
Низкий

2.9 Low

CVSS3