Описание
xml-rs vulnerable to denial of service via invalid token in XML document
The xml-rs crate >= 0.8.9 and < 0.8.14 for Rust and Crab allows a denial of service (panic) via an invalid <! token (such as <!DOCTYPEs/%<!A nesting) in an XML document.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2023-34411
- https://github.com/netvl/xml-rs/pull/226
- https://github.com/00xc/xml-rs/commit/0f084d45aa53e4a27476961785f59f2bd7d59a9f
- https://github.com/netvl/xml-rs/commit/014d808be900c85a0afc5ccdfe668be040d175aa
- https://github.com/netvl/xml-rs/commit/c09549a187e62d39d40467f129e64abf32efc35c
- https://github.com/netvl/xml-rs/compare/0.8.13...0.8.14
Пакеты
Наименование
xml-rs
rust
Затронутые версииВерсия исправления
>= 0.8.9, < 0.8.14
0.8.14
Связанные уязвимости
CVSS3: 7.5
ubuntu
больше 2 лет назад
The xml-rs crate before 0.8.14 for Rust and Crab allows a denial of service (panic) via an invalid <! token (such as <!DOCTYPEs/%<!A nesting) in an XML document. The earliest affected version is 0.8.9.
CVSS3: 7.5
nvd
больше 2 лет назад
The xml-rs crate before 0.8.14 for Rust and Crab allows a denial of service (panic) via an invalid <! token (such as <!DOCTYPEs/%<!A nesting) in an XML document. The earliest affected version is 0.8.9.
CVSS3: 7.5
debian
больше 2 лет назад
The xml-rs crate before 0.8.14 for Rust and Crab allows a denial of se ...