Show plain JSON{"id": "CVE-2025-3416", "cveTags": [], "metrics": {"cvssMetricV31": [{"type": "Primary", "source": "secalert@redhat.com", "cvssData": {"scope": "UNCHANGED", "version": "3.1", "baseScore": 3.7, "attackVector": "NETWORK", "baseSeverity": "LOW", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L", "integrityImpact": "NONE", "userInteraction": "NONE", "attackComplexity": "HIGH", "availabilityImpact": "LOW", "privilegesRequired": "NONE", "confidentialityImpact": "NONE"}, "impactScore": 1.4, "exploitabilityScore": 2.2}]}, "published": "2025-04-08T19:15:53.717", "references": [{"url": "https://access.redhat.com/security/cve/CVE-2025-3416", "source": "secalert@redhat.com"}, {"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2357560", "source": "secalert@redhat.com"}, {"url": "https://github.com/sfackler/rust-openssl", "source": "secalert@redhat.com"}, {"url": "https://github.com/sfackler/rust-openssl/commit/87085bd67896b7f92e6de35d081f607a334beae4", "source": "secalert@redhat.com"}, {"url": "https://github.com/sfackler/rust-openssl/pull/2390", "source": "secalert@redhat.com"}, {"url": "https://rustsec.org/advisories/RUSTSEC-2025-0022.html", "source": "secalert@redhat.com"}], "vulnStatus": "Awaiting Analysis", "weaknesses": [{"type": "Primary", "source": "secalert@redhat.com", "description": [{"lang": "en", "value": "CWE-416"}]}], "descriptions": [{"lang": "en", "value": "A flaw was found in OpenSSL's handling of the properties argument in certain functions. This vulnerability can allow use-after-free exploitation, which may result in undefined behavior or incorrect property parsing, leading to OpenSSL treating the input as an empty string."}, {"lang": "es", "value": "Se detect\u00f3 una falla en el gestionamiento del argumento de propiedades por parte de OpenSSL en ciertas funciones. Esta vulnerabilidad puede permitir la explotaci\u00f3n de la funci\u00f3n \"use after free\", lo que puede resultar en un comportamiento indefinido o un an\u00e1lisis incorrecto de las propiedades, lo que hace que OpenSSL trate la entrada como una cadena vac\u00eda."}], "lastModified": "2025-04-09T20:02:41.860", "sourceIdentifier": "secalert@redhat.com"}