An issue was discovered in the openssl crate before 0.10.9 for Rust. A use-after-free occurs in CMS Signing.
No PoCs from references.
- https://github.com/ARPSyndicate/cvemon
- https://github.com/Artisan-Lab/Rust-memory-safety-bugs
- https://github.com/MaineK00n/go-osv
- https://github.com/chnzzh/OpenSSL-CVE-lib