Description
rust-base64 version <= 0.5.1 is vulnerable to a buffer overflow when calculating the size of a buffer to use when encoding base64 using the 'encode_config_buf' and 'encode_config' functions
References (1)
Core 1
Core References
Third Party Advisory x_refsource_misc
https://github.com/RustSec/advisory-db/blob/master/crates/base64/RUSTSEC-2017-0004.toml
Scores
CVSS v3
9.8
EPSS
0.0153
EPSS Percentile
71.7%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-119
Status
published
Products (2)
crates.io/base64
0 - 0.5.2crates.io
rust-base64_project/rust-base64
< 0.5.1
Published
Jan 02, 2018
Tracked Since
Feb 18, 2026