logo

GHSA-gw89-822v-8v8g openssl

Package

Manager: cargo
Name: openssl
Vulnerable Version: <0

Severity

Level: Medium

CVSS v3.1: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:L

CVSS v4.0: N/A

EPSS: N/A pctlN/A

Details

Duplicate Advisory: `openssl` `X509VerifyParamRef::set_host` buffer over-read ### Duplicate Advisory This advisory has been withdrawn because it is a duplicate of GHSA-xcf7-rvmh-g6q4. This link is maintained to preserve external references. ### Original Description The openssl crate before 0.10.55 for Rust allows an out-of-bounds read via an empty string to X509VerifyParamRef::set_host.

Metadata

Created: 2025-07-28T03:31:04Z
Modified: 2025-07-28T15:54:34Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/07/GHSA-gw89-822v-8v8g/GHSA-gw89-822v-8v8g.json
CWE IDs: ["CWE-126"]
Alternative ID: N/A
Finding: N/A
Auto approve: 0