CVE-2019-15544

HIGH7.5EPSS 2.7%

Out of Memory in stream::read_raw_bytes_into()

Published: 8/25/2021Modified: 11/8/2023
Also known as:GHSA-mh6h-f25p-98f8RUSTSEC-2019-0003

Description

Affected versions of this crate called Vec::reserve() on user-supplied input. This allows an attacker to cause an Out of Memory condition while calling the vulnerable method on untrusted data.

Affected packages (2)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1HIGH7.5CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

References (9)