Vulnerability Name: | CVE-2020-36323 (CCN-200156) | ||||||||||||||||||
Assigned: | 2020-12-23 | ||||||||||||||||||
Published: | 2020-12-23 | ||||||||||||||||||
Updated: | 2021-04-27 | ||||||||||||||||||
Summary: | In the standard library in Rust before 1.52.0, there is an optimization for joining strings that can cause uninitialized bytes to be exposed (or the program to crash) if the borrowed string changes after its length is checked. | ||||||||||||||||||
CVSS v3 Severity: | 8.2 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H) 7.1 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H/E:U/RL:O/RC:C)
7.1 High (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H/E:U/RL:O/RC:C)
7.1 High (REDHAT Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H/E:U/RL:O/RC:C)
| ||||||||||||||||||
CVSS v2 Severity: | 6.4 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:P)
| ||||||||||||||||||
Vulnerability Type: | CWE-134 CWE-20 | ||||||||||||||||||
Vulnerability Consequences: | Denial of Service | ||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2020-36323 Source: XF Type: UNKNOWN rust-cve202036323-dos(200156) Source: CCN Type: Rust GIT Repository API soundness issue in join() implementation of [Borrow Source: MISC Type: Patch, Third Party Advisory https://github.com/rust-lang/rust/issues/80335 Source: MISC Type: Patch, Third Party Advisory https://github.com/rust-lang/rust/pull/81728 Source: MISC Type: Patch, Third Party Advisory https://github.com/rust-lang/rust/pull/81728#issuecomment-821549174 Source: MISC Type: Patch, Third Party Advisory https://github.com/rust-lang/rust/pull/81728#issuecomment-824904190 Source: FEDORA Type: Mailing List, Third Party Advisory FEDORA-2021-d0ba1901ca Source: FEDORA Type: Mailing List, Third Party Advisory FEDORA-2021-d7f74f0250 Source: FEDORA Type: Mailing List, Third Party Advisory FEDORA-2021-b1ba54add6 | ||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration RedHat 1: Configuration RedHat 2: ![]() | ||||||||||||||||||
Oval Definitions | |||||||||||||||||||
| |||||||||||||||||||
BACK |