Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w7j2-35mf-95p7

Опубликовано: 25 авг. 2021
Источник: github
Github: Прошло ревью
CVSS3: 9.8

Описание

Incorrect check on buffer length in rand_core

An issue was discovered in the rand_core crate before 0.6.2 for Rust. Because read_u32_into and read_u64_into mishandle certain buffer-length checks, a random number generator may be seeded with too little data. The vulnerability was introduced in v0.6.0. The advisory doesn't apply to earlier minor version numbers.

Because read_u32_into and read_u64_into mishandle certain buffer-length checks, a random number generator may be seeded with too little data.

Пакеты

Наименование

rand_core

rust
Затронутые версииВерсия исправления

>= 0.6.0, < 0.6.2

0.6.2

EPSS

Процентиль: 66%
0.01243
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-330

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 5 лет назад

An issue was discovered in the rand_core crate before 0.6.2 for Rust. Because read_u32_into and read_u64_into mishandle certain buffer-length checks, a random number generator may be seeded with too little data.

CVSS3: 9.8
nvd
больше 5 лет назад

An issue was discovered in the rand_core crate before 0.6.2 for Rust. Because read_u32_into and read_u64_into mishandle certain buffer-length checks, a random number generator may be seeded with too little data.

CVSS3: 9.8
msrc
6 месяцев назад

An issue was discovered in the rand_core crate before 0.6.2 for Rust. Because read_u32_into and read_u64_into mishandle certain buffer-length checks a random number generator may be seeded with too little data.

CVSS3: 9.8
debian
больше 5 лет назад

An issue was discovered in the rand_core crate before 0.6.2 for Rust. ...

EPSS

Процентиль: 66%
0.01243
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-330