You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
An issue was discovered in the simple_asn1 crate 0.6.0 before 0.6.1 for Rust. There is a panic if UTCTime data, supplied by a remote attacker, has a second character greater than 0x7f.
Mend Note: Converted from WS-2021-0425, on 2022-11-07.
CVE-2021-45711 - High Severity Vulnerability
A simple DER/ASN.1 encoding/decoding library.
Library home page: https://crates.io/api/v1/crates/simple_asn1/0.5.4/download
Path to dependency file: /Cargo.toml
Path to vulnerable library: /Cargo.toml
Dependency Hierarchy:
Found in HEAD commit: 0210244c73d8447f5fea76a1f812bd534796c09a
Found in base branch: master
An issue was discovered in the simple_asn1 crate 0.6.0 before 0.6.1 for Rust. There is a panic if UTCTime data, supplied by a remote attacker, has a second character greater than 0x7f.
Mend Note: Converted from WS-2021-0425, on 2022-11-07.
Publish Date: 2021-12-26
URL: CVE-2021-45711
Base Score Metrics:
Type: Upgrade version
Origin: https://rustsec.org/advisories/RUSTSEC-2021-0125.html
Release Date: 2021-12-27
Fix Resolution: simple_asn1 - 0.6.1
Step up your Open Source Security Game with Mend here
The text was updated successfully, but these errors were encountered: