PT-2019-14841 · Rust · Linea
Published
2019-09-14
·
Updated
2021-08-25
·
CVE-2019-16880
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
linea crate versions through 0.9.4
Description
The issue is related to a double free in the
Matrix::zip elements method. This occurs when the given trait implementation might panic, allowing an attacker to corrupt or take control of the memory.Recommendations
For versions through 0.9.4, update to a version where the flaw has been corrected by the maintainer, such as the fix provided by Phosphorus15.
Exploit
Fix
Double Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Linea