Lucene search

K
ubuntucveUbuntu.comUB:CVE-2021-29922
HistoryAug 07, 2021 - 12:00 a.m.

CVE-2021-29922

2021-08-0700:00:00
ubuntu.com
ubuntu.com
12
rust
library
vulnerability
ip address
parsing
access control

CVSS2

6.4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:P/A:P

CVSS3

9.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

EPSS

0.005

Percentile

76.3%

library/std/src/net/parser.rs in Rust before 1.53.0 does not properly
consider extraneous zero characters at the beginning of an IP address
string, which (in some situations) allows attackers to bypass access
control that is based on IP addresses, because of unexpected octal
interpretation.

OSVersionArchitecturePackageVersionFilename
ubuntu20.04noarchrustc< 1.53.0+dfsg1+llvm-4ubuntu1~20.04.1UNKNOWN
ubuntu22.04noarchrustc< 1.53.0+dfsg1+llvm-4ubuntu1UNKNOWN
ubuntu14.04noarchrustc< anyUNKNOWN
ubuntu16.04noarchrustc< anyUNKNOWN

CVSS2

6.4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:P/A:P

CVSS3

9.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

EPSS

0.005

Percentile

76.3%