Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xmgf-hq76-4vx2

Опубликовано: 22 апр. 2026
Источник: github
Github: Прошло ревью
CVSS4: 1.7

Описание

rust-opennssl has an Out-of-bounds read in PEM password callback when returning an oversized length

The *_from_pem_callback APIs did not validate the length returned by the user's callback. A password callback that returns a value larger than the buffer it was given can cause some versions of OpenSSL to over-read this buffer. OpenSSL 3.x is not affected by this.

Пакеты

Наименование

openssl

rust
Затронутые версииВерсия исправления

>= 0.9.0, < 0.10.78

0.10.78

EPSS

Процентиль: 22%
0.00294
Низкий

1.7 Low

CVSS4

Дефекты

CWE-125
CWE-1284

Связанные уязвимости

CVSS3: 9.1
ubuntu
3 месяца назад

rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.0 to before 0.10.78, the *_from_pem_callback APIs did not validate the length returned by the user's callback. A password callback that returns a value larger than the buffer it was given can cause some versions of OpenSSL to over-read this buffer. OpenSSL 3.x is not affected by this. This vulnerability is fixed in 0.10.78.

CVSS3: 9.1
nvd
3 месяца назад

rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.0 to before 0.10.78, the *_from_pem_callback APIs did not validate the length returned by the user's callback. A password callback that returns a value larger than the buffer it was given can cause some versions of OpenSSL to over-read this buffer. OpenSSL 3.x is not affected by this. This vulnerability is fixed in 0.10.78.

msrc
3 месяца назад

rust-openssl: Out-of-bounds read in PEM password callback when user callback returns an oversized length

CVSS3: 9.1
debian
3 месяца назад

rust-openssl provides OpenSSL bindings for the Rust programming langua ...

suse-cvrf
15 дней назад

Security update for aws-nitro-enclaves-cli

EPSS

Процентиль: 22%
0.00294
Низкий

1.7 Low

CVSS4

Дефекты

CWE-125
CWE-1284