Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v362-2895-h9r2

Опубликовано: 07 янв. 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Use After Free in lru

Lru crate has two functions for getting an iterator. Both iterators give references to key and value. Calling specific functions, like pop(), will remove and free the value, and but it's still possible to access the reference of value which is already dropped causing use after free.

Пакеты

Наименование

lru

rust
Затронутые версииВерсия исправления

< 0.7.1

0.7.1

EPSS

Процентиль: 51%
0.0028
Низкий

7.5 High

CVSS3

Дефекты

CWE-416

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 4 лет назад

An issue was discovered in the lru crate before 0.7.1 for Rust. The iterators have a use-after-free, as demonstrated by an access after a pop operation.

CVSS3: 7.5
nvd
около 4 лет назад

An issue was discovered in the lru crate before 0.7.1 for Rust. The iterators have a use-after-free, as demonstrated by an access after a pop operation.

EPSS

Процентиль: 51%
0.0028
Низкий

7.5 High

CVSS3

Дефекты

CWE-416