Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-c86p-w88r-qvqr

Опубликовано: 09 мая 2025
Источник: github
Github: Прошло ревью
CVSS3: 5.3

Описание

ring has some AES functions that may panic when overflow checking is enabled in

A flaw was found in Rust's Ring package. A panic may be triggered when overflow checking is enabled. In the QUIC protocol, this flaw allows an attacker to induce this panic by sending a specially crafted packet. It will likely occur unintentionally in 1 out of every 2**32 packets sent or received.

Пакеты

Наименование

ring

rust
Затронутые версииВерсия исправления

< 0.17.13

0.17.13

EPSS

Процентиль: 35%
0.00138
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-770

Связанные уязвимости

CVSS3: 5.3
ubuntu
около 1 месяца назад

A flaw was found in Rust's Ring package. A panic may be triggered when overflow checking is enabled. In the QUIC protocol, this flaw allows an attacker to induce this panic by sending a specially crafted packet. It will likely occur unintentionally in 1 out of every 2**32 packets sent or received.

CVSS3: 5.3
redhat
4 месяца назад

A flaw was found in Rust's Ring package. A panic may be triggered when overflow checking is enabled. In the QUIC protocol, this flaw allows an attacker to induce this panic by sending a specially crafted packet. It will likely occur unintentionally in 1 out of every 2**32 packets sent or received.

CVSS3: 5.3
nvd
около 1 месяца назад

A flaw was found in Rust's Ring package. A panic may be triggered when overflow checking is enabled. In the QUIC protocol, this flaw allows an attacker to induce this panic by sending a specially crafted packet. It will likely occur unintentionally in 1 out of every 2**32 packets sent or received.

CVSS3: 5.3
debian
около 1 месяца назад

A flaw was found in Rust's Ring package. A panic may be triggered when ...

EPSS

Процентиль: 35%
0.00138
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-770