CVE-2021-29922
Summary
| CVE | CVE-2021-29922 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-08-07 17:15:00 UTC |
| Updated | 2022-11-07 16:36:00 UTC |
| Description | library/std/src/net/parser.rs in Rust before 1.53.0 does not properly consider extraneous zero characters at the beginning of an IP address string, which (in some situations) allows attackers to bypass access control that is based on IP addresses, because of unexpected octal interpretation. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Rust: Multiple Vulnerabilities (GLSA 202210-09) — Gentoo security | GENTOO | security.gentoo.org | |
| security/SICK-2021-015.md at master · sickcodes/security · GitHub | MISC | github.com | |
| Ipv4Addr: Incorrect Parsing for Octal format IP string · Issue #83648 · rust-lang/rust · GitHub | MISC | github.com | |
| defcon.org/html/defcon-29/dc-29-speakers.html | MISC | defcon.org | |
| Disallow octal format in Ipv4 string by xu-cheng · Pull Request #83652 · rust-lang/rust · GitHub | MISC | github.com | |
| std::net::Ipv4Addr - Rust | MISC | doc.rust-lang.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 159481 Oracle Enterprise Linux Security Update for rust-toolset:ol8 (ELSA-2021-4270)
- 183683 Debian Security Update for rustc (CVE-2021-29922)
- 239784 Red Hat Update for rust-toolset:rhel8 security (RHSA-2021:4270)
- 296065 Oracle Solaris 11.4 Support Repository Update (SRU) 39.107.1 Missing (CPUOCT2021)
- 501922 Alpine Linux Security Update for rust
- 505392 Alpine Linux Security Update for rust
- 710640 Gentoo Linux Rust Multiple Vulnerabilities (GLSA 202210-09)
- 900297 CBL-Mariner Linux Security Update for rust 1.47.0
- 940385 AlmaLinux Security Update for rust-toolset:rhel8 (ALSA-2021:4270)
- 960734 Rocky Linux Security Update for rust-toolset:rhel8 (RLSA-2021:4270)