Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x4qm-mcjq-v2gf

Опубликовано: 25 авг. 2021
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Overflow in prost-types

Affected versions of this crate contained a bug in which untrusted input could cause an overflow and panic when converting a Timestamp to SystemTime. It is recommended to upgrade to prost-types v0.8 and switch the usage of From for SystemTime to TryFrom for SystemTime.

Пакеты

Наименование

prost-types

rust
Затронутые версииВерсия исправления

< 0.8.0

0.8.0

EPSS

Процентиль: 51%
0.0028
Низкий

7.5 High

CVSS3

Дефекты

CWE-120
CWE-190

Связанные уязвимости

CVSS3: 7.5
nvd
больше 4 лет назад

An issue was discovered in the prost-types crate before 0.8.0 for Rust. An overflow can occur during conversion from Timestamp to SystemTime.

EPSS

Процентиль: 51%
0.0028
Низкий

7.5 High

CVSS3

Дефекты

CWE-120
CWE-190