Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jqpv-jm4m-86j9

Опубликовано: 06 янв. 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Use After Free in libpulse-binding

Affected versions contained a pair of use-after-free issues with the objects returned by the get_format_info and get_context methods of Stream objects. These objects were mistakenly being constructed without setting an important flag to prevent destruction of the underlying C objects they reference upon their own destruction.

Пакеты

Наименование

libpulse-binding

rust
Затронутые версииВерсия исправления

< 1.2.1

1.2.1

EPSS

Процентиль: 64%
0.00478
Низкий

7.5 High

CVSS3

Дефекты

CWE-416

Связанные уязвимости

CVSS3: 7.5
nvd
около 4 лет назад

An issue was discovered in the libpulse-binding crate before 1.2.1 for Rust. get_context can cause a use-after-free.

EPSS

Процентиль: 64%
0.00478
Низкий

7.5 High

CVSS3

Дефекты

CWE-416