imPC@ndo IT

Tracker / CVE-2019-15544

CVE-2019-15544

High 7.5

An issue was discovered in the protobuf crate before 2.6.0 for Rust. Attackers can exhaust all memory via Vec::reserve calls.

Affected products and versions

apache hbase
rust-protobuf_project rust-protobuf · … → 1.7.5
rust-protobuf_project rust-protobuf · 2.0.0 → 2.6.0

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References