CVE-2020-25016
Summary
| CVE | CVE-2020-25016 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-08-29 16:15:00 UTC |
| Updated | 2021-07-21 11:39:00 UTC |
| Description | A safety violation was discovered in the rgb crate before 0.8.20 for Rust, leading to (for example) dereferencing of arbitrary pointers or disclosure of uninitialized memory. This occurs because structs can be treated as bytes for read and write operations. |
Risk And Classification
Problem Types: CWE-119 | CWE-843
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Rgb-rust Project | Rgb-rust | All | All | All | All |
| Application | Rgb-rust Project | Rgb-rust | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| ComponentBytes is unsound · Issue #35 · kornelski/rust-rgb · GitHub | MISC | github.com | Exploit, Third Party Advisory |
| RUSTSEC-2020-0029: rgb: Allows viewing and modifying arbitrary structs as bytes › RustSec Advisory Database | MISC | rustsec.org | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.