Описание
A flaw was found in Rustls 0.23.13 and related APIs. This vulnerability allows denial of service (panic) via a fragmented TLS ClientHello message.
Ссылки
- Vendor Advisory
- Vendor Advisory
- Third Party Advisory
- Product
- ExploitIssue TrackingVendor Advisory
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:rustls_project:rustls:0.23.13:*:*:*:*:*:*:*
EPSS
Процентиль: 44%
0.0022
Низкий
5.3 Medium
CVSS3
7.5 High
CVSS3
Дефекты
CWE-248
Связанные уязвимости
CVSS3: 5.3
ubuntu
около 1 года назад
A flaw was found in Rustls 0.23.13 and related APIs. This vulnerability allows denial of service (panic) via a fragmented TLS ClientHello message.
CVSS3: 5.3
redhat
около 1 года назад
A flaw was found in Rustls 0.23.13 and related APIs. This vulnerability allows denial of service (panic) via a fragmented TLS ClientHello message.
CVSS3: 5.3
msrc
5 месяцев назад
Rustls: rustls network-reachable panic in `acceptor::accept`
CVSS3: 5.3
debian
около 1 года назад
A flaw was found in Rustls 0.23.13 and related APIs. This vulnerabilit ...
EPSS
Процентиль: 44%
0.0022
Низкий
5.3 Medium
CVSS3
7.5 High
CVSS3
Дефекты
CWE-248