mirror of
https://github.com/OMGeeky/advisory-db.git
synced 2026-01-04 10:40:34 +01:00
Add kamadak-exif DoS (#1411)
This commit is contained in:
committed by
GitHub
parent
7f6f544c39
commit
3834127c26
22
crates/kamadak-exif/RUSTSEC-0000-0000.md
Normal file
22
crates/kamadak-exif/RUSTSEC-0000-0000.md
Normal file
@@ -0,0 +1,22 @@
|
||||
```toml
|
||||
[advisory]
|
||||
id = "RUSTSEC-0000-0000"
|
||||
package = "kamadak-exif"
|
||||
date = "2021-01-04"
|
||||
url = "https://github.com/kamadak/exif-rs/commit/1b05eab57e484cd7d576d4357b9cda7fdc57df8c"
|
||||
categories = ["denial-of-service"]
|
||||
cvss = "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
|
||||
keywords = ["untrusted-data", "dos"]
|
||||
aliases = ["CVE-2021-21235", "GHSA-px9g-8hgv-jvg2"]
|
||||
|
||||
[affected]
|
||||
functions = { "kamadak_exif::Reader::read_from_container" = [">= 0.5.2, < 0.5.3"] }
|
||||
|
||||
[versions]
|
||||
patched = [">= 0.5.3"]
|
||||
unaffected = ["< 0.5.2"]
|
||||
|
||||
```
|
||||
# kamadak-exif DoS with untrusted PNG data
|
||||
|
||||
Attacker crafted data can cause a infinite loop leading to DoS if used with untrusted data.
|
||||
Reference in New Issue
Block a user