The Rust Programming Language Standard Library 1.34.x before 1.34.2 contains a stabilized method which, if overridden, can violate Rust's safety guarantees and cause memory unsafety. If the `Error::type_id` method is overridden then any type can be safely cast to any other type, causing memory safety vulnerabilities in safe code (e.g., out-of-bounds write or read). Code that does not manually implement Error::type_id is unaffected.
CVSS Details
- CVSS 3.1 Base Score: 8.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade rust | Aug 22, 2024 | May 13, 2019 |
| Freebsd | — | Upgrade rust | May 15, 2019 | May 15, 2019 |
| Suse | — | Upgrade rustUpgrade cargo-docUpgrade rustfmtUpgrade rust-analysisUpgrade rust-std-staticUpgrade rust-docUpgrade cargoUpgrade rust-gdbUpgrade rust-srcUpgrade rlsUpgrade clippyUpgrade rust-cbindgen | Sep 27, 2019 | May 13, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub