The Rust Programming Language Standard Library 1.18.0 and later is affected by: CWE-200: Information Exposure. The impact is: Contents of uninitialized memory could be printed to string or to log file. The component is: Debug trait implementation for std::collections::vec_deque::Iter. The attack vector is: The program needs to invoke debug printing for iterator over an empty VecDeque. The fixed version is: 1.30.0, nightly versions after commit b85e4cc8fadaabd41da5b9645c08c68b8f89908d.
CVSS Details
- CVSS 3.1 Base Score: 5.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade rustc | Jul 30, 2024 | Jul 15, 2019 |
| Oracle Solaris | — | Upgrade developer/rust/rustc to version 1.35.0-11.4.15.0.1.1.0 on Solaris 11.4Upgrade developer/rust/cargo-vendor to version 0.1.23-11.4.15.0.1.1.0 on Solaris 11.4Upgrade developer/rust/cargo to version 1.35.0-11.4.15.0.1.1.0 on Solaris 11.4 | Nov 20, 2019 | Jul 15, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub