Описание
Ghidra before 12.0.3 contains an out-of-memory vulnerability in the rust_demangle function that allocates unbounded output buffers without size limits. Attackers can craft malicious Rust symbol names in binaries to trigger exponential memory allocation, causing process crashes during binary analysis.
Ссылки
- ExploitVendor Advisory
- Third Party Advisory
- ExploitVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 12.0.3 (исключая)
cpe:2.3:a:nsa:ghidra:*:*:*:*:*:*:*:*
EPSS
Процентиль: 5%
0.00151
Низкий
5.5 Medium
CVSS3
Дефекты
CWE-789
Связанные уязвимости
CVSS3: 5.5
debian
2 месяца назад
Ghidra before 12.0.3 contains an out-of-memory vulnerability in the ru ...
EPSS
Процентиль: 5%
0.00151
Низкий
5.5 Medium
CVSS3
Дефекты
CWE-789