GHSA-g4h2-4wvh-grc5

    Dashboard / Vulnerabilities / GHSA-g4h2-4wvh-grc5

    GHSA-g4h2-4wvh-grc5

    Published: 6 Jan 2022Last Modified: 8 Nov 2023

    Summary: Uncontrolled Resource Consumption in simple_asn1

    Details: An issue was discovered in the simple_asn1 crate 0.6.0 before 0.6.1 for Rust. There is a panic if UTCTime data, supplied by a remote attacker, has a second character greater than 0x7f.

    Affected packages

    Package

    Name: simple_asn1

    Purl: pkg:cargo/simple_asn1

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0.6.0
    Fixed -0.6.1

    Affected versions

    0.6.0

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-g4h2-4wvh-grc5 | CVE-DB