Логотип exploitDog
bind:"GHSA-m5pq-gvj9-9vr8" OR bind:"CVE-2022-24713"
Консоль
Логотип exploitDog

exploitDog

bind:"GHSA-m5pq-gvj9-9vr8" OR bind:"CVE-2022-24713"

Количество 26

Количество 26

github логотип

GHSA-m5pq-gvj9-9vr8

почти 4 года назад

Rust's regex crate vulnerable to regular expression denial of service

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2022-24713

почти 4 года назад

regex is an implementation of regular expressions for the Rust language. The regex crate features built-in mitigations to prevent denial of service attacks caused by untrusted regexes, or untrusted input matched by trusted regexes. Those (tunable) mitigations already provide sane defaults to prevent attacks. This guarantee is documented and it's considered part of the crate's API. Unfortunately a bug was discovered in the mitigations designed to prevent untrusted regexes to take an arbitrary amount of time during parsing, and it's possible to craft regexes that bypass such mitigations. This makes it possible to perform denial of service attacks by sending specially crafted regexes to services accepting user-controlled, untrusted regexes. All versions of the regex crate before or equal to 1.5.4 are affected by this issue. The fix is include starting from regex 1.5.5. All users accepting user-controlled regexes are recommended to upgrade immediately to the latest version of the regex ...

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2022-24713

почти 4 года назад

regex is an implementation of regular expressions for the Rust language. The regex crate features built-in mitigations to prevent denial of service attacks caused by untrusted regexes, or untrusted input matched by trusted regexes. Those (tunable) mitigations already provide sane defaults to prevent attacks. This guarantee is documented and it's considered part of the crate's API. Unfortunately a bug was discovered in the mitigations designed to prevent untrusted regexes to take an arbitrary amount of time during parsing, and it's possible to craft regexes that bypass such mitigations. This makes it possible to perform denial of service attacks by sending specially crafted regexes to services accepting user-controlled, untrusted regexes. All versions of the regex crate before or equal to 1.5.4 are affected by this issue. The fix is include starting from regex 1.5.5. All users accepting user-controlled regexes are recommended to upgrade immediately to the latest version of the regex ...

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2022-24713

почти 4 года назад

regex is an implementation of regular expressions for the Rust language. The regex crate features built-in mitigations to prevent denial of service attacks caused by untrusted regexes, or untrusted input matched by trusted regexes. Those (tunable) mitigations already provide sane defaults to prevent attacks. This guarantee is documented and it's considered part of the crate's API. Unfortunately a bug was discovered in the mitigations designed to prevent untrusted regexes to take an arbitrary amount of time during parsing, and it's possible to craft regexes that bypass such mitigations. This makes it possible to perform denial of service attacks by sending specially crafted regexes to services accepting user-controlled, untrusted regexes. All versions of the regex crate before or equal to 1.5.4 are affected by this issue. The fix is include starting from regex 1.5.5. All users accepting user-controlled regexes are recommended to upgrade immediately to the latest version of the regex cra

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2022-24713

больше 1 года назад

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2022-24713

почти 4 года назад

regex is an implementation of regular expressions for the Rust languag ...

CVSS3: 7.5
EPSS: Низкий
fstec логотип

BDU:2022-02373

почти 4 года назад

Уязвимость реализации проверки регулярных выражений (regex для Rust) веб-браузеров Firefox, Firefox ESR и почтового клиента Thunderbird, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 4.3
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:1844-1

почти 3 года назад

Security update for aws-nitro-enclaves-cli

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:4073-1

около 3 лет назад

Security update for sccache

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:3949-1

около 3 лет назад

Security update for rustup

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2024:0294-1

больше 1 года назад

Security update for kanidm

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:3526-1

больше 2 лет назад

Security update for sccache

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2022:1127-1

почти 4 года назад

Security update for MozillaFirefox

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:1127-1

почти 4 года назад

Security update for MozillaFirefox

EPSS: Низкий
suse-cvrf логотип

SUSE-RU-2022:14935-1

почти 4 года назад

Recommended update for MozillaFirefox

EPSS: Низкий
suse-cvrf логотип

SUSE-RU-2022:1125-1

почти 4 года назад

Security update for MozillaFirefox

EPSS: Низкий
suse-cvrf логотип

SUSE-RU-2022:1114-1

почти 4 года назад

Security update for MozillaFirefox

EPSS: Низкий
rocky логотип

RLSA-2022:1287

почти 4 года назад

Important: firefox security update

EPSS: Низкий
oracle-oval логотип

ELSA-2022-1287

почти 4 года назад

ELSA-2022-1287: firefox security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2022-1284

почти 4 года назад

ELSA-2022-1284: firefox security update (IMPORTANT)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-m5pq-gvj9-9vr8

Rust's regex crate vulnerable to regular expression denial of service

CVSS3: 7.5
7%
Низкий
почти 4 года назад
ubuntu логотип
CVE-2022-24713

regex is an implementation of regular expressions for the Rust language. The regex crate features built-in mitigations to prevent denial of service attacks caused by untrusted regexes, or untrusted input matched by trusted regexes. Those (tunable) mitigations already provide sane defaults to prevent attacks. This guarantee is documented and it's considered part of the crate's API. Unfortunately a bug was discovered in the mitigations designed to prevent untrusted regexes to take an arbitrary amount of time during parsing, and it's possible to craft regexes that bypass such mitigations. This makes it possible to perform denial of service attacks by sending specially crafted regexes to services accepting user-controlled, untrusted regexes. All versions of the regex crate before or equal to 1.5.4 are affected by this issue. The fix is include starting from regex 1.5.5. All users accepting user-controlled regexes are recommended to upgrade immediately to the latest version of the regex ...

CVSS3: 7.5
7%
Низкий
почти 4 года назад
redhat логотип
CVE-2022-24713

regex is an implementation of regular expressions for the Rust language. The regex crate features built-in mitigations to prevent denial of service attacks caused by untrusted regexes, or untrusted input matched by trusted regexes. Those (tunable) mitigations already provide sane defaults to prevent attacks. This guarantee is documented and it's considered part of the crate's API. Unfortunately a bug was discovered in the mitigations designed to prevent untrusted regexes to take an arbitrary amount of time during parsing, and it's possible to craft regexes that bypass such mitigations. This makes it possible to perform denial of service attacks by sending specially crafted regexes to services accepting user-controlled, untrusted regexes. All versions of the regex crate before or equal to 1.5.4 are affected by this issue. The fix is include starting from regex 1.5.5. All users accepting user-controlled regexes are recommended to upgrade immediately to the latest version of the regex ...

CVSS3: 7.5
7%
Низкий
почти 4 года назад
nvd логотип
CVE-2022-24713

regex is an implementation of regular expressions for the Rust language. The regex crate features built-in mitigations to prevent denial of service attacks caused by untrusted regexes, or untrusted input matched by trusted regexes. Those (tunable) mitigations already provide sane defaults to prevent attacks. This guarantee is documented and it's considered part of the crate's API. Unfortunately a bug was discovered in the mitigations designed to prevent untrusted regexes to take an arbitrary amount of time during parsing, and it's possible to craft regexes that bypass such mitigations. This makes it possible to perform denial of service attacks by sending specially crafted regexes to services accepting user-controlled, untrusted regexes. All versions of the regex crate before or equal to 1.5.4 are affected by this issue. The fix is include starting from regex 1.5.5. All users accepting user-controlled regexes are recommended to upgrade immediately to the latest version of the regex cra

CVSS3: 7.5
7%
Низкий
почти 4 года назад
msrc логотип
CVSS3: 7.5
7%
Низкий
больше 1 года назад
debian логотип
CVE-2022-24713

regex is an implementation of regular expressions for the Rust languag ...

CVSS3: 7.5
7%
Низкий
почти 4 года назад
fstec логотип
BDU:2022-02373

Уязвимость реализации проверки регулярных выражений (regex для Rust) веб-браузеров Firefox, Firefox ESR и почтового клиента Thunderbird, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 4.3
7%
Низкий
почти 4 года назад
suse-cvrf логотип
SUSE-SU-2023:1844-1

Security update for aws-nitro-enclaves-cli

почти 3 года назад
suse-cvrf логотип
SUSE-SU-2022:4073-1

Security update for sccache

около 3 лет назад
suse-cvrf логотип
SUSE-SU-2022:3949-1

Security update for rustup

около 3 лет назад
suse-cvrf логотип
openSUSE-SU-2024:0294-1

Security update for kanidm

больше 1 года назад
suse-cvrf логотип
SUSE-SU-2023:3526-1

Security update for sccache

больше 2 лет назад
suse-cvrf логотип
openSUSE-SU-2022:1127-1

Security update for MozillaFirefox

почти 4 года назад
suse-cvrf логотип
SUSE-SU-2022:1127-1

Security update for MozillaFirefox

почти 4 года назад
suse-cvrf логотип
SUSE-RU-2022:14935-1

Recommended update for MozillaFirefox

почти 4 года назад
suse-cvrf логотип
SUSE-RU-2022:1125-1

Security update for MozillaFirefox

почти 4 года назад
suse-cvrf логотип
SUSE-RU-2022:1114-1

Security update for MozillaFirefox

почти 4 года назад
rocky логотип
RLSA-2022:1287

Important: firefox security update

почти 4 года назад
oracle-oval логотип
ELSA-2022-1287

ELSA-2022-1287: firefox security update (IMPORTANT)

почти 4 года назад
oracle-oval логотип
ELSA-2022-1284

ELSA-2022-1284: firefox security update (IMPORTANT)

почти 4 года назад

Уязвимостей на страницу