PT-2021-12006 · Rust+6 · Rust+6
Qwaz
·
Published
2021-04-14
·
Updated
2022-04-28
·
CVE-2020-36323
CVSS v3.1
8.2
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H |
Name of the Vulnerable Software and Affected Versions:
Rust versions prior to 1.52.0
Description:
The issue is related to an optimization in the standard library for joining strings. This optimization can cause uninitialized bytes to be exposed or the program to crash if the borrowed string changes after its length is checked.
Recommendations:
For versions prior to 1.52.0, update to version 1.52.0 or later to resolve the issue.
Fix
Use of Externally-Controlled Format String
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Centos
Debian
Red Hat
Rocky Linux
Rust