Panic Induction in Rust's Cookie Crate Due to Max-Age Handling
CVE-2017-18589

7.5HIGH

Key Information:

Status
Vendor
CVE Published:
26 August 2019

What is CVE-2017-18589?

A vulnerability has been identified in the cookie crate for Rust, impacting versions prior to 0.7.6. This issue arises from the handling of large integers specified in the Max-Age attribute of cookies, potentially leading to runtime panics. Developers utilizing the affected versions should review their implementation of the cookie crate to ensure they are not exposing their applications to unexpected failures due to this vulnerability.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.