Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-61912
HistoryAug 11, 2022 - 12:00 a.m.

Apache Avro Denial of Service Vulnerability

2022-08-1100:00:00
China National Vulnerability Database
www.cnvd.org.cn
14
apache
avro
denial of service
vulnerability
rust sdk
integer overflow
corrupted files
attack
crash
program

EPSS

0.001

Percentile

33.9%

Apache Avro is a data serialization system from the Apache Foundation, Inc. A denial of service vulnerability exists in versions of Apache Avro Rust prior to 0.14.0, which stems from an integer overflow when reading corrupted .avro files in the Avro Rust SDK, and can be exploited by an attacker to crash a program.

EPSS

0.001

Percentile

33.9%

Related for CNVD-2022-61912