Логотип exploitDog
bind:"CVE-2025-58160"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2025-58160"

Количество 9

Количество 9

ubuntu логотип

CVE-2025-58160

4 месяца назад

tracing is a framework for instrumenting Rust programs to collect structured, event-based diagnostic information. Prior to version 0.3.20, tracing-subscriber was vulnerable to ANSI escape sequence injection attacks. Untrusted user input containing ANSI escape sequences could be injected into terminal output when logged, potentially allowing attackers to manipulate terminal title bars, clear screens or modify terminal display, and potentially mislead users through terminal manipulation. tracing-subscriber version 0.3.20 fixes this vulnerability by escaping ANSI control characters when writing events to destinations that may be printed to the terminal. A workaround involves avoiding printing logs to terminal emulators without escaping ANSI control sequences.

EPSS: Низкий
redhat логотип

CVE-2025-58160

4 месяца назад

tracing is a framework for instrumenting Rust programs to collect structured, event-based diagnostic information. Prior to version 0.3.20, tracing-subscriber was vulnerable to ANSI escape sequence injection attacks. Untrusted user input containing ANSI escape sequences could be injected into terminal output when logged, potentially allowing attackers to manipulate terminal title bars, clear screens or modify terminal display, and potentially mislead users through terminal manipulation. tracing-subscriber version 0.3.20 fixes this vulnerability by escaping ANSI control characters when writing events to destinations that may be printed to the terminal. A workaround involves avoiding printing logs to terminal emulators without escaping ANSI control sequences.

CVSS3: 3.1
EPSS: Низкий
nvd логотип

CVE-2025-58160

4 месяца назад

tracing is a framework for instrumenting Rust programs to collect structured, event-based diagnostic information. Prior to version 0.3.20, tracing-subscriber was vulnerable to ANSI escape sequence injection attacks. Untrusted user input containing ANSI escape sequences could be injected into terminal output when logged, potentially allowing attackers to manipulate terminal title bars, clear screens or modify terminal display, and potentially mislead users through terminal manipulation. tracing-subscriber version 0.3.20 fixes this vulnerability by escaping ANSI control characters when writing events to destinations that may be printed to the terminal. A workaround involves avoiding printing logs to terminal emulators without escaping ANSI control sequences.

EPSS: Низкий
debian логотип

CVE-2025-58160

4 месяца назад

tracing is a framework for instrumenting Rust programs to collect stru ...

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:4091-1

около 1 месяца назад

Security update for cargo-packaging, rust-bindgen

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:3869-1

около 2 месяцев назад

Security update for himmelblau

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:03082-1

3 месяца назад

Security update for python-maturin

EPSS: Низкий
github логотип

GHSA-xwfj-jgwm-7wp5

4 месяца назад

Tracing logging user input may result in poisoning logs with ANSI escape sequences

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2025-20114-1

20 дней назад

Security update for himmelblau

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2025-58160

tracing is a framework for instrumenting Rust programs to collect structured, event-based diagnostic information. Prior to version 0.3.20, tracing-subscriber was vulnerable to ANSI escape sequence injection attacks. Untrusted user input containing ANSI escape sequences could be injected into terminal output when logged, potentially allowing attackers to manipulate terminal title bars, clear screens or modify terminal display, and potentially mislead users through terminal manipulation. tracing-subscriber version 0.3.20 fixes this vulnerability by escaping ANSI control characters when writing events to destinations that may be printed to the terminal. A workaround involves avoiding printing logs to terminal emulators without escaping ANSI control sequences.

0%
Низкий
4 месяца назад
redhat логотип
CVE-2025-58160

tracing is a framework for instrumenting Rust programs to collect structured, event-based diagnostic information. Prior to version 0.3.20, tracing-subscriber was vulnerable to ANSI escape sequence injection attacks. Untrusted user input containing ANSI escape sequences could be injected into terminal output when logged, potentially allowing attackers to manipulate terminal title bars, clear screens or modify terminal display, and potentially mislead users through terminal manipulation. tracing-subscriber version 0.3.20 fixes this vulnerability by escaping ANSI control characters when writing events to destinations that may be printed to the terminal. A workaround involves avoiding printing logs to terminal emulators without escaping ANSI control sequences.

CVSS3: 3.1
0%
Низкий
4 месяца назад
nvd логотип
CVE-2025-58160

tracing is a framework for instrumenting Rust programs to collect structured, event-based diagnostic information. Prior to version 0.3.20, tracing-subscriber was vulnerable to ANSI escape sequence injection attacks. Untrusted user input containing ANSI escape sequences could be injected into terminal output when logged, potentially allowing attackers to manipulate terminal title bars, clear screens or modify terminal display, and potentially mislead users through terminal manipulation. tracing-subscriber version 0.3.20 fixes this vulnerability by escaping ANSI control characters when writing events to destinations that may be printed to the terminal. A workaround involves avoiding printing logs to terminal emulators without escaping ANSI control sequences.

0%
Низкий
4 месяца назад
debian логотип
CVE-2025-58160

tracing is a framework for instrumenting Rust programs to collect stru ...

0%
Низкий
4 месяца назад
suse-cvrf логотип
SUSE-SU-2025:4091-1

Security update for cargo-packaging, rust-bindgen

0%
Низкий
около 1 месяца назад
suse-cvrf логотип
SUSE-SU-2025:3869-1

Security update for himmelblau

0%
Низкий
около 2 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:03082-1

Security update for python-maturin

0%
Низкий
3 месяца назад
github логотип
GHSA-xwfj-jgwm-7wp5

Tracing logging user input may result in poisoning logs with ANSI escape sequences

0%
Низкий
4 месяца назад
suse-cvrf логотип
openSUSE-SU-2025-20114-1

Security update for himmelblau

20 дней назад

Уязвимостей на страницу