Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-c86p-w88r-qvqr

Опубликовано: 09 мая 2025
Источник: github
Github: Прошло ревью
CVSS3: 5.3

Описание

ring has some AES functions that may panic when overflow checking is enabled in

A flaw was found in Rust's Ring package. A panic may be triggered when overflow checking is enabled. In the QUIC protocol, this flaw allows an attacker to induce this panic by sending a specially crafted packet. It will likely occur unintentionally in 1 out of every 2**32 packets sent or received.

Пакеты

Наименование

ring

rust
Затронутые версииВерсия исправления

< 0.17.13

0.17.13

EPSS

Процентиль: 39%
0.00172
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-770

Связанные уязвимости

CVSS3: 5.3
ubuntu
6 месяцев назад

A flaw was found in Rust's Ring package. A panic may be triggered when overflow checking is enabled. In the QUIC protocol, this flaw allows an attacker to induce this panic by sending a specially crafted packet. It will likely occur unintentionally in 1 out of every 2**32 packets sent or received.

CVSS3: 5.3
redhat
8 месяцев назад

A flaw was found in Rust's Ring package. A panic may be triggered when overflow checking is enabled. In the QUIC protocol, this flaw allows an attacker to induce this panic by sending a specially crafted packet. It will likely occur unintentionally in 1 out of every 2**32 packets sent or received.

CVSS3: 5.3
nvd
6 месяцев назад

A flaw was found in Rust's Ring package. A panic may be triggered when overflow checking is enabled. In the QUIC protocol, this flaw allows an attacker to induce this panic by sending a specially crafted packet. It will likely occur unintentionally in 1 out of every 2**32 packets sent or received.

CVSS3: 3.7
msrc
3 месяца назад

Ring: some aes functions may panic when overflow checking is enabled in ring

CVSS3: 5.3
debian
6 месяцев назад

A flaw was found in Rust's Ring package. A panic may be triggered when ...

EPSS

Процентиль: 39%
0.00172
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-770