Debian Rust-Rustls vulnerabilities
2 known vulnerabilities affecting debian/rust-rustls.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1LOW1
Vulnerabilities
Page 1 of 1
CVE-2024-32650HIGHCVSS 7.5fixed in rust-rustls 0.21.12-1 (forky)2024
CVE-2024-32650 [HIGH] CVE-2024-32650: rust-rustls - Rustls is a modern TLS library written in Rust. `rustls::ConnectionCommon::compl...
Rustls is a modern TLS library written in Rust. `rustls::ConnectionCommon::complete_io` could fall into an infinite loop based on network input. When using a blocking rustls server, if a client send a `close_notify` message immediately after `client_hello`, the server's `complete_io` will get in an infinite loop. This vulnerability is fixed in 0.23.5, 0.22.4, an
debian
CVE-2024-11738LOWCVSS 5.32024
CVE-2024-11738 [MEDIUM] CVE-2024-11738: rust-rustls - A flaw was found in Rustls 0.23.13 and related APIs. This vulnerability allows d...
A flaw was found in Rustls 0.23.13 and related APIs. This vulnerability allows denial of service (panic) via a fragmented TLS ClientHello message.
Scope: local
bookworm: resolved
forky: resolved
sid: resolved
trixie: resolved
debian