PT-2019-14538 · Renderdoc · Renderdoc
Publicado
2019-09-02
·
Atualizado
2021-08-25
·
CVE-2019-16142
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
renderdoc crate versions prior to 0.5.0
Description
The issue arises from methods in the renderdoc crate that take
self by immutable reference, which is incompatible with multi-threaded applications and can lead to unexpected behavior when called without synchronization. This technically unsound behavior can result in unpredictable outcomes.Recommendations
For versions prior to 0.5.0, update to release 0.5.0 to resolve the issue. As a temporary workaround, consider synchronizing access to methods that take
self by immutable reference to minimize the risk of exploitation.Correção
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Renderdoc