sfackler/rust-openssl

sfackler/rust-openssl

Releases276
Frequency2 weeks 4 days
Last Release
Stars1.54K
OpenSSL bindings for Rust

CVE History

CVEPublishedCVSS v3CVSS v2
4.5 MEDIUM

The openssl crate before 0.10.55 for Rust allows an out-of-bounds read via an empty string to X509VerifyParamRef::set_host.

3.7 LOW

A flaw was found in OpenSSL's handling of the properties argument in certain functions. This vulnerability can allow use-after-free exploitation, which may result in undefined behavior or incorrect property parsing, leading to OpenSSL treating the input as an empty string.