Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3gxf-9r58-2ghg

Опубликовано: 24 мар. 2023
Источник: github
Github: Прошло ревью

Описание

openssl X509NameBuilder::build returned object is not thread safe

OpenSSL has a modified bit that it can set on on X509_NAME objects. If this bit is set then the object is not thread-safe even when it appears the code is not modifying the value.

Thanks to David Benjamin (Google) for reporting this issue.

Пакеты

Наименование

openssl

rust
Затронутые версииВерсия исправления

>= 0.9.7, < 0.10.48

0.10.48