PT-2020-17612 · Rust · Chunky Crate

Published

2020-08-25

·

Updated

2021-08-25

·

CVE-2020-36433

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions chunky crate through 2020-08-25
Description The issue concerns the Chunk API not honoring an alignment requirement, which can lead to the creation of unaligned references. This results in undefined behavior.
Recommendations For versions of the chunky crate through 2020-08-25, consider updating to a version that properly honors alignment requirements to prevent undefined behavior. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-36433
GHSA-QG24-8XJ4-GJ2H
RUSTSEC-2020-0035

Affected Products

Chunky Crate