Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-1000810

Опубликовано: 08 окт. 2018
Источник: nvd
CVSS3: 9.8
CVSS2: 7.5
EPSS Низкий

Описание

The Rust Programming Language Standard Library version 1.29.0, 1.28.0, 1.27.2, 1.27.1, 127.0, 126.2, 126.1, 126.0 contains a CWE-680: Integer Overflow to Buffer Overflow vulnerability in standard library that can result in buffer overflow. This attack appear to be exploitable via str::repeat, passed a large number, can overflow an internal buffer. This vulnerability appears to have been fixed in 1.29.1.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:rust-lang:rust:1.26.0:*:*:*:*:*:*:*
cpe:2.3:a:rust-lang:rust:1.26.1:*:*:*:*:*:*:*
cpe:2.3:a:rust-lang:rust:1.26.2:*:*:*:*:*:*:*
cpe:2.3:a:rust-lang:rust:1.27.0:*:*:*:*:*:*:*
cpe:2.3:a:rust-lang:rust:1.27.1:*:*:*:*:*:*:*
cpe:2.3:a:rust-lang:rust:1.27.2:*:*:*:*:*:*:*
cpe:2.3:a:rust-lang:rust:1.28.0:*:*:*:*:*:*:*
cpe:2.3:a:rust-lang:rust:1.29.0:*:*:*:*:*:*:*

EPSS

Процентиль: 86%
0.02955
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-190

Связанные уязвимости

CVSS3: 9.8
ubuntu
почти 8 лет назад

The Rust Programming Language Standard Library version 1.29.0, 1.28.0, 1.27.2, 1.27.1, 127.0, 126.2, 126.1, 126.0 contains a CWE-680: Integer Overflow to Buffer Overflow vulnerability in standard library that can result in buffer overflow. This attack appear to be exploitable via str::repeat, passed a large number, can overflow an internal buffer. This vulnerability appears to have been fixed in 1.29.1.

CVSS3: 7.4
redhat
почти 8 лет назад

The Rust Programming Language Standard Library version 1.29.0, 1.28.0, 1.27.2, 1.27.1, 127.0, 126.2, 126.1, 126.0 contains a CWE-680: Integer Overflow to Buffer Overflow vulnerability in standard library that can result in buffer overflow. This attack appear to be exploitable via str::repeat, passed a large number, can overflow an internal buffer. This vulnerability appears to have been fixed in 1.29.1.

CVSS3: 9.8
debian
почти 8 лет назад

The Rust Programming Language Standard Library version 1.29.0, 1.28.0, ...

CVSS3: 9.8
github
около 4 лет назад

The Rust Programming Language Standard Library version 1.29.0, 1.28.0, 1.27.2, 1.27.1, 127.0, 126.2, 126.1, 126.0 contains a CWE-680: Integer Overflow to Buffer Overflow vulnerability in standard library that can result in buffer overflow. This attack appear to be exploitable via str::repeat, passed a large number, can overflow an internal buffer. This vulnerability appears to have been fixed in 1.29.1.

EPSS

Процентиль: 86%
0.02955
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-190