CVE-2019-15544

Severity
7.5HIGH
EPSS
2.7%
top 14.13%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 26
Latest updateAug 25

Description

An issue was discovered in the protobuf crate before 2.6.0 for Rust. Attackers can exhaust all memory via Vec::reserve calls.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages3 packages

crates.ioprotobuf0.0.0-01.7.5+2
NVDapache/hbase2.2.3

🔴Vulnerability Details

4
GHSA
Uncontrolled memory consumption in protobuf2021-08-25
OSV
Uncontrolled memory consumption in protobuf2021-08-25
CVEList
CVE-2019-15544: An issue was discovered in the protobuf crate before 22019-08-26
OSV
Out of Memory in stream::read_raw_bytes_into()2019-06-08
CVE-2019-15544 (HIGH CVSS 7.5) | An issue was discovered in the prot | cvebase.io