Описание
xmas-elf potential out-of-bounds read with a malformed ELF file and the HashTable API.
Affected versions of this crate only validated the index argument of HashTable::get_bucket and HashTable::get_chain against the input-controlled bucket_count and chain_count fields, but not against the size of the ELF section. As a result, a malformed ELF file could trigger out-of-bounds reads in a consumer of the HashTable API by setting these fields to inappropriately large values that would fall outside the relevant hash table section, and by introducing correspondingly out-of-bounds hash table indexes elsewhere in the ELF file.
Пакеты
Наименование
xmas-elf
rust
Затронутые версииВерсия исправления
< 0.10
0.10
6.9 Medium
CVSS4
Дефекты
CWE-125
6.9 Medium
CVSS4
Дефекты
CWE-125