Gnome

Librest

2 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.25%
  • Veröffentlicht 22.07.2026 16:12:03
  • Zuletzt bearbeitet 01.09.2026 18:17:39

A flaw was found in librest. The PKCE implementation for OAuth authorization uses the GRand function from the GLib API, a cryptographically insecure pseudo-random number generator. Because the generated "code verifier" lacks sufficient cryptographic ...

  • EPSS 3.47%
  • Veröffentlicht 18.08.2017 18:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

The OAuth implementation in librest before 0.7.93 incorrectly truncates the pointer returned by the rest_proxy_call_get_url function, which allows remote attackers to cause a denial of service (application crash) via running the EnsureCredentials met...