3.3
CVE-2023-53159
- EPSS 0.33%
- Veröffentlicht 28.07.2025 00:00:00
- Zuletzt bearbeitet 17.09.2026 16:42:20
- Erkennungen
The openssl crate before 0.10.55 for Rust allows an out-of-bounds read via an empty string to X509VerifyParamRef::set_host.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.33% | 0.254 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 3.3 | 1.8 | 1.4 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
|
| MITRE | 4.5 | 1.4 | 2.7 |
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:L
|
CWE-126 Buffer Over-read
The product reads from a buffer using buffer access mechanisms such as indexes or pointers that reference memory locations after the targeted buffer.
https://crates.io/crates/openssl
https://github.com/sfackler/rust-openssl/issues/1965
https://rustsec.org/advisories/RUSTSEC-2023-0044.html