VYPR

rpm package

opensuse/shadowsocks-rust&distro=openSUSE Tumbleweed

pkg:rpm/opensuse/shadowsocks-rust&distro=openSUSE%20Tumbleweed

Vulnerabilities (5)

  • CVE-2026-93599HigSep 18, 2026
    affected < 1.25.0-2.1fixed 1.25.0-2.1

    rustls-webpki through 0.103.12 (and 0.104.0-alpha releases before 0.104.0-alpha.7) contains a reachable panic in bit_string_flags() in src/der.rs. The input guard fails to reject a named-bit BIT STRING whose content is exactly [0x00] (zero padding bits and no data bytes), so raw_

  • CVE-2026-25541HigFeb 4, 2026
    affected < 1.25.0-1.1fixed 1.25.0-1.1

    Bytes is a utility library for working with bytes. From version 1.2.1 to before 1.11.1, Bytes is vulnerable to integer overflow in BytesMut::reserve. In the unique reclaim path of BytesMut::reserve, if the condition "v_capacity >= new_cap + offset" uses an unchecked addition. Whe

  • CVE-2025-3416LowApr 8, 2025
    affected < 1.25.0-1.1fixed 1.25.0-1.1

    A flaw was found in OpenSSL's handling of the properties argument in certain functions. This vulnerability can allow use-after-free exploitation, which may result in undefined behavior or incorrect property parsing, leading to OpenSSL treating the input as an empty string.

  • CVE-2024-32650HigApr 19, 2024
    affected < 1.18.3-1.1fixed 1.18.3-1.1

    Rustls is a modern TLS library written in Rust. `rustls::ConnectionCommon::complete_io` could fall into an infinite loop based on network input. When using a blocking rustls server, if a client send a `close_notify` message immediately after `client_hello`, the server's `complete

  • CVE-2023-42811MedSep 22, 2023
    affected < 1.16.2-1.1fixed 1.16.2-1.1

    aes-gcm is a pure Rust implementation of the AES-GCM. Starting in version 0.10.0 and prior to version 0.10.3, in the AES GCM implementation of decrypt_in_place_detached, the decrypted ciphertext (i.e. the correct plaintext) is exposed even if tag verification fails. If a program