Описание
An issue was discovered in the abomonation crate through 2021-10-17 for Rust. Because transmute operations are insufficiently constrained, there can be an information leak or ASLR bypass.
Ссылки
- Third Party Advisory
- Vendor Advisory
- Third Party Advisory
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 0.7.3 (включая)
cpe:2.3:a:abomonation_project:abomonation:*:*:*:*:*:rust:*:*
EPSS
Процентиль: 52%
0.00291
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-668
Связанные уязвимости
CVSS3: 7.5
github
около 4 лет назад
Abomonation transmutes &T to and from &[u8] without sufficient constraints
EPSS
Процентиль: 52%
0.00291
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-668