Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-c86p-w88r-qvqr

Опубликовано: 09 мая 2025
Источник: github
Github: Прошло ревью
CVSS3: 5.3

Описание

Duplicate Advisory: ring has some AES functions that may panic when overflow checking is enabled in

Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-4p46-pwfr-66x6. This link is maintained to preserve external references.

Original Description

A flaw was found in Rust's Ring package. A panic may be triggered when overflow checking is enabled. In the QUIC protocol, this flaw allows an attacker to induce this panic by sending a specially crafted packet. It will likely occur unintentionally in 1 out of every 2**32 packets sent or received.

Пакеты

Наименование

ring

rust
Затронутые версииВерсия исправления

< 0.17.13

0.17.13

5.3 Medium

CVSS3

Дефекты

CWE-770

5.3 Medium

CVSS3

Дефекты

CWE-770