Логотип exploitDog
bind:"GHSA-m5pq-gvj9-9vr8" OR bind:"CVE-2022-24713"
Консоль
Логотип exploitDog

exploitDog

bind:"GHSA-m5pq-gvj9-9vr8" OR bind:"CVE-2022-24713"

Количество 24

Количество 24

github логотип

GHSA-m5pq-gvj9-9vr8

больше 3 лет назад

Rust's regex crate vulnerable to regular expression denial of service

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2022-24713

больше 3 лет назад

regex is an implementation of regular expressions for the Rust language. The regex crate features built-in mitigations to prevent denial of service attacks caused by untrusted regexes, or untrusted input matched by trusted regexes. Those (tunable) mitigations already provide sane defaults to prevent attacks. This guarantee is documented and it's considered part of the crate's API. Unfortunately a bug was discovered in the mitigations designed to prevent untrusted regexes to take an arbitrary amount of time during parsing, and it's possible to craft regexes that bypass such mitigations. This makes it possible to perform denial of service attacks by sending specially crafted regexes to services accepting user-controlled, untrusted regexes. All versions of the regex crate before or equal to 1.5.4 are affected by this issue. The fix is include starting from regex 1.5.5. All users accepting user-controlled regexes are recommended to upgrade immediately to the latest version of the regex ...

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2022-24713

около 3 лет назад

regex is an implementation of regular expressions for the Rust language. The regex crate features built-in mitigations to prevent denial of service attacks caused by untrusted regexes, or untrusted input matched by trusted regexes. Those (tunable) mitigations already provide sane defaults to prevent attacks. This guarantee is documented and it's considered part of the crate's API. Unfortunately a bug was discovered in the mitigations designed to prevent untrusted regexes to take an arbitrary amount of time during parsing, and it's possible to craft regexes that bypass such mitigations. This makes it possible to perform denial of service attacks by sending specially crafted regexes to services accepting user-controlled, untrusted regexes. All versions of the regex crate before or equal to 1.5.4 are affected by this issue. The fix is include starting from regex 1.5.5. All users accepting user-controlled regexes are recommended to upgrade immediately to the latest version of the regex ...

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2022-24713

больше 3 лет назад

regex is an implementation of regular expressions for the Rust language. The regex crate features built-in mitigations to prevent denial of service attacks caused by untrusted regexes, or untrusted input matched by trusted regexes. Those (tunable) mitigations already provide sane defaults to prevent attacks. This guarantee is documented and it's considered part of the crate's API. Unfortunately a bug was discovered in the mitigations designed to prevent untrusted regexes to take an arbitrary amount of time during parsing, and it's possible to craft regexes that bypass such mitigations. This makes it possible to perform denial of service attacks by sending specially crafted regexes to services accepting user-controlled, untrusted regexes. All versions of the regex crate before or equal to 1.5.4 are affected by this issue. The fix is include starting from regex 1.5.5. All users accepting user-controlled regexes are recommended to upgrade immediately to the latest version of the regex cra

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2022-24713

12 месяцев назад

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2022-24713

больше 3 лет назад

regex is an implementation of regular expressions for the Rust languag ...

CVSS3: 7.5
EPSS: Низкий
fstec логотип

BDU:2022-02373

около 3 лет назад

Уязвимость реализации проверки регулярных выражений (regex для Rust) веб-браузеров Firefox, Firefox ESR и почтового клиента Thunderbird, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 4.3
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:1844-1

около 2 лет назад

Security update for aws-nitro-enclaves-cli

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:4073-1

больше 2 лет назад

Security update for sccache

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:3949-1

больше 2 лет назад

Security update for rustup

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2024:0294-1

9 месяцев назад

Security update for kanidm

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:3526-1

почти 2 года назад

Security update for sccache

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2022:1127-1

около 3 лет назад

Security update for MozillaFirefox

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:1127-1

около 3 лет назад

Security update for MozillaFirefox

EPSS: Низкий
suse-cvrf логотип

SUSE-RU-2022:14935-1

около 3 лет назад

Recommended update for MozillaFirefox

EPSS: Низкий
suse-cvrf логотип

SUSE-RU-2022:1125-1

около 3 лет назад

Security update for MozillaFirefox

EPSS: Низкий
suse-cvrf логотип

SUSE-RU-2022:1114-1

около 3 лет назад

Security update for MozillaFirefox

EPSS: Низкий
redos логотип

ROS-20220412-03

около 3 лет назад

Множественные уязвимости Mozilla Thunderbird

EPSS: Низкий
redos логотип

ROS-20220412-02

около 3 лет назад

Множественные уязвимости Mozilla Firefox

EPSS: Низкий
oracle-oval логотип

ELSA-2022-1287

около 3 лет назад

ELSA-2022-1287: firefox security update (IMPORTANT)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-m5pq-gvj9-9vr8

Rust's regex crate vulnerable to regular expression denial of service

CVSS3: 7.5
8%
Низкий
больше 3 лет назад
ubuntu логотип
CVE-2022-24713

regex is an implementation of regular expressions for the Rust language. The regex crate features built-in mitigations to prevent denial of service attacks caused by untrusted regexes, or untrusted input matched by trusted regexes. Those (tunable) mitigations already provide sane defaults to prevent attacks. This guarantee is documented and it's considered part of the crate's API. Unfortunately a bug was discovered in the mitigations designed to prevent untrusted regexes to take an arbitrary amount of time during parsing, and it's possible to craft regexes that bypass such mitigations. This makes it possible to perform denial of service attacks by sending specially crafted regexes to services accepting user-controlled, untrusted regexes. All versions of the regex crate before or equal to 1.5.4 are affected by this issue. The fix is include starting from regex 1.5.5. All users accepting user-controlled regexes are recommended to upgrade immediately to the latest version of the regex ...

CVSS3: 7.5
8%
Низкий
больше 3 лет назад
redhat логотип
CVE-2022-24713

regex is an implementation of regular expressions for the Rust language. The regex crate features built-in mitigations to prevent denial of service attacks caused by untrusted regexes, or untrusted input matched by trusted regexes. Those (tunable) mitigations already provide sane defaults to prevent attacks. This guarantee is documented and it's considered part of the crate's API. Unfortunately a bug was discovered in the mitigations designed to prevent untrusted regexes to take an arbitrary amount of time during parsing, and it's possible to craft regexes that bypass such mitigations. This makes it possible to perform denial of service attacks by sending specially crafted regexes to services accepting user-controlled, untrusted regexes. All versions of the regex crate before or equal to 1.5.4 are affected by this issue. The fix is include starting from regex 1.5.5. All users accepting user-controlled regexes are recommended to upgrade immediately to the latest version of the regex ...

CVSS3: 7.5
8%
Низкий
около 3 лет назад
nvd логотип
CVE-2022-24713

regex is an implementation of regular expressions for the Rust language. The regex crate features built-in mitigations to prevent denial of service attacks caused by untrusted regexes, or untrusted input matched by trusted regexes. Those (tunable) mitigations already provide sane defaults to prevent attacks. This guarantee is documented and it's considered part of the crate's API. Unfortunately a bug was discovered in the mitigations designed to prevent untrusted regexes to take an arbitrary amount of time during parsing, and it's possible to craft regexes that bypass such mitigations. This makes it possible to perform denial of service attacks by sending specially crafted regexes to services accepting user-controlled, untrusted regexes. All versions of the regex crate before or equal to 1.5.4 are affected by this issue. The fix is include starting from regex 1.5.5. All users accepting user-controlled regexes are recommended to upgrade immediately to the latest version of the regex cra

CVSS3: 7.5
8%
Низкий
больше 3 лет назад
msrc логотип
CVSS3: 7.5
8%
Низкий
12 месяцев назад
debian логотип
CVE-2022-24713

regex is an implementation of regular expressions for the Rust languag ...

CVSS3: 7.5
8%
Низкий
больше 3 лет назад
fstec логотип
BDU:2022-02373

Уязвимость реализации проверки регулярных выражений (regex для Rust) веб-браузеров Firefox, Firefox ESR и почтового клиента Thunderbird, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 4.3
8%
Низкий
около 3 лет назад
suse-cvrf логотип
SUSE-SU-2023:1844-1

Security update for aws-nitro-enclaves-cli

около 2 лет назад
suse-cvrf логотип
SUSE-SU-2022:4073-1

Security update for sccache

больше 2 лет назад
suse-cvrf логотип
SUSE-SU-2022:3949-1

Security update for rustup

больше 2 лет назад
suse-cvrf логотип
openSUSE-SU-2024:0294-1

Security update for kanidm

9 месяцев назад
suse-cvrf логотип
SUSE-SU-2023:3526-1

Security update for sccache

почти 2 года назад
suse-cvrf логотип
openSUSE-SU-2022:1127-1

Security update for MozillaFirefox

около 3 лет назад
suse-cvrf логотип
SUSE-SU-2022:1127-1

Security update for MozillaFirefox

около 3 лет назад
suse-cvrf логотип
SUSE-RU-2022:14935-1

Recommended update for MozillaFirefox

около 3 лет назад
suse-cvrf логотип
SUSE-RU-2022:1125-1

Security update for MozillaFirefox

около 3 лет назад
suse-cvrf логотип
SUSE-RU-2022:1114-1

Security update for MozillaFirefox

около 3 лет назад
redos логотип
ROS-20220412-03

Множественные уязвимости Mozilla Thunderbird

около 3 лет назад
redos логотип
ROS-20220412-02

Множественные уязвимости Mozilla Firefox

около 3 лет назад
oracle-oval логотип
ELSA-2022-1287

ELSA-2022-1287: firefox security update (IMPORTANT)

около 3 лет назад

Уязвимостей на страницу