GHSA-4fcv-w3qc-ppgg: rust-openssl Use-After-Free in `Md::fetch` and `Cipher::fetch`
N/A
CVSS Score
Basic Information
CVE ID
-
GHSA ID
EPSS Score
-
CWE
Published
4/4/2025
Updated
4/4/2025
KEV Status
No
Technology
Rust
Technical Details
CVSS Vector
-
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| openssl | rust | >= 0.10.39, < 0.10.72 | 0.10.72 |
Vulnerability Intelligence
Miggo AI
Root Cause Analysis
The analysis involved examining the patches provided and understanding the changes made to fix the vulnerability. The functions Cipher::fetch and Md::fetch were identified as vulnerable due to their improper handling of the properties argument, leading to a use-after-free. The patches directly point to these functions as the locations of the vulnerability.