Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9c48-w39g-hm26

Опубликовано: 06 янв. 2026
Источник: github
Github: Прошло ревью
CVSS4: 2.7

Описание

rsa crate has potential panic on a prime being equal to 1

When creating a RSA private key from its components, the construction panics, instead of returning an error, when one of the primes is 1.

Discovered by Christian Reitter from Radically Open Security during a security review for Proton AG.

Пакеты

Наименование

rsa

rust
Затронутые версииВерсия исправления

<= 0.9.9

0.9.10

EPSS

Процентиль: 13%
0.00042
Низкий

2.7 Low

CVSS4

Дефекты

CWE-703

Связанные уязвимости

ubuntu
6 дней назад

The `rsa` crate is an RSA implementation written in rust. Prior to version 0.9.10, when creating a RSA private key from its components, the construction panics instead of returning an error when one of the primes is `1`. Version 0.9.10 fixes the issue.

nvd
7 дней назад

The `rsa` crate is an RSA implementation written in rust. Prior to version 0.9.10, when creating a RSA private key from its components, the construction panics instead of returning an error when one of the primes is `1`. Version 0.9.10 fixes the issue.

debian
7 дней назад

The `rsa` crate is an RSA implementation written in rust. Prior to ver ...

EPSS

Процентиль: 13%
0.00042
Низкий

2.7 Low

CVSS4

Дефекты

CWE-703