Описание
An issue was discovered in the rand_core crate before 0.4.2 for Rust. Casting of byte slices to integer slices mishandles alignment constraints.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| rust-rand-core | fixed | 0.5.0-1 | package | |
| rust-rand-core | ignored | buster | package | |
| rust-rand-core-0.3 | removed | package | ||
| rust-rand-core-0.2 | removed | package | ||
| rust-rand-core-0.2 | ignored | buster | package |
Примечания
https://rustsec.org/advisories/RUSTSEC-2019-0035.html
https://github.com/rust-random/rand/blob/master/rand_core/CHANGELOG.md#050---2019-06-06
Связанные уязвимости
CVSS3: 9.8
ubuntu
почти 6 лет назад
An issue was discovered in the rand_core crate before 0.4.2 for Rust. Casting of byte slices to integer slices mishandles alignment constraints.
CVSS3: 9.8
nvd
почти 6 лет назад
An issue was discovered in the rand_core crate before 0.4.2 for Rust. Casting of byte slices to integer slices mishandles alignment constraints.