Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9cc5-2pq7-hfj8

Опубликовано: 26 мар. 2025
Источник: github
Github: Прошло ревью
CVSS4: 6.9

Описание

xmas-elf potential out-of-bounds read with a malformed ELF file and the HashTable API.

Affected versions of this crate only validated the index argument of HashTable::get_bucket and HashTable::get_chain against the input-controlled bucket_count and chain_count fields, but not against the size of the ELF section. As a result, a malformed ELF file could trigger out-of-bounds reads in a consumer of the HashTable API by setting these fields to inappropriately large values that would fall outside the relevant hash table section, and by introducing correspondingly out-of-bounds hash table indexes elsewhere in the ELF file.

Пакеты

Наименование

xmas-elf

rust
Затронутые версииВерсия исправления

< 0.10

0.10

6.9 Medium

CVSS4

Дефекты

CWE-125

6.9 Medium

CVSS4

Дефекты

CWE-125