Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w7j2-35mf-95p7

Опубликовано: 25 авг. 2021
Источник: github
Github: Прошло ревью
CVSS3: 9.8

Описание

Incorrect check on buffer length in rand_core

An issue was discovered in the rand_core crate before 0.6.2 for Rust. Because read_u32_into and read_u64_into mishandle certain buffer-length checks, a random number generator may be seeded with too little data. The vulnerability was introduced in v0.6.0. The advisory doesn't apply to earlier minor version numbers.

Because read_u32_into and read_u64_into mishandle certain buffer-length checks, a random number generator may be seeded with too little data.

Пакеты

Наименование

rand_core

rust
Затронутые версииВерсия исправления

>= 0.6.0, < 0.6.2

0.6.2

EPSS

Процентиль: 64%
0.00468
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-330

Связанные уязвимости

CVSS3: 9.8
ubuntu
почти 5 лет назад

An issue was discovered in the rand_core crate before 0.6.2 for Rust. Because read_u32_into and read_u64_into mishandle certain buffer-length checks, a random number generator may be seeded with too little data.

CVSS3: 9.8
nvd
почти 5 лет назад

An issue was discovered in the rand_core crate before 0.6.2 for Rust. Because read_u32_into and read_u64_into mishandle certain buffer-length checks, a random number generator may be seeded with too little data.

CVSS3: 9.8
msrc
больше 1 года назад

Описание отсутствует

CVSS3: 9.8
debian
почти 5 лет назад

An issue was discovered in the rand_core crate before 0.6.2 for Rust. ...

EPSS

Процентиль: 64%
0.00468
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-330