Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xcf7-rvmh-g6q4

Опубликовано: 21 июн. 2023
Источник: github
Github: Прошло ревью
CVSS3: 4.5

Описание

openssl X509VerifyParamRef::set_host buffer over-read

When this function was passed an empty string, openssl would attempt to call strlen on it, reading arbitrary memory until it reached a NUL byte.

Пакеты

Наименование

openssl

rust
Затронутые версииВерсия исправления

>= 0.10.0, < 0.10.55

0.10.55

EPSS

Процентиль: 26%
0.00331
Низкий

4.5 Medium

CVSS3

Дефекты

CWE-126

Связанные уязвимости

CVSS3: 4.5
ubuntu
около 1 года назад

The openssl crate before 0.10.55 for Rust allows an out-of-bounds read via an empty string to X509VerifyParamRef::set_host.

CVSS3: 5.7
redhat
около 1 года назад

The openssl crate before 0.10.55 for Rust allows an out-of-bounds read via an empty string to X509VerifyParamRef::set_host.

CVSS3: 4.5
nvd
около 1 года назад

The openssl crate before 0.10.55 for Rust allows an out-of-bounds read via an empty string to X509VerifyParamRef::set_host.

msrc
12 месяцев назад

The openssl crate before 0.10.55 for Rust allows an out-of-bounds read via an empty string to X509VerifyParamRef::set_host.

CVSS3: 4.5
debian
около 1 года назад

The openssl crate before 0.10.55 for Rust allows an out-of-bounds read ...

EPSS

Процентиль: 26%
0.00331
Низкий

4.5 Medium

CVSS3

Дефекты

CWE-126