PT-2020-17656 · Rust · Bite Crate

Published

2020-12-31

·

Updated

2022-06-16

·

CVE-2020-36511

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions bite crate through 2020-12-31
Description The issue concerns the read::BiteReadExpandedExt::read framed max function, which may read from uninitialized memory locations. This occurs when affected versions of the crate call a user-provided Read implementation on an uninitialized buffer. In Rust, Read on an uninitialized buffer is defined as undefined behavior.
Recommendations For the bite crate through 2020-12-31, consider restricting the use of the read framed max function until a fix is available. As a temporary workaround, avoid using the read::BiteReadExpandedExt::read framed max function to prevent potential issues with uninitialized memory locations. At the moment, there is no information about a newer version that contains a fix for this issue.

Fix

Use of Uninitialized Resource

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-36511
GHSA-72R2-RG28-47V9
GHSA-V2CH-FC8F-QM33
RUSTSEC-2020-0153

Affected Products

Bite Crate