9.8
CVSSv3

CVE-2019-15552

Published: 26/08/2019 Updated: 05/09/2019
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

An issue exists in the libflate crate prior to 0.1.25 for Rust. MultiDecoder::read has a use-after-free, leading to arbitrary code execution.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

libflate project libflate

Vendor Advisories

Debian Bug report logs - #969899 rust-libflate: CVE-2019-15552: use-after-free vulnerability on panic in client code Package: src:rust-libflate; Maintainer for src:rust-libflate is Debian Rust Maintainers <pkg-rust-maintainers@alioth-listsdebiannet>; Reported by: Alexander Kjäll <alexanderkjall@gmailcom> Date: Tu ...