Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mmc9-pwm7-qj5w

Опубликовано: 25 авг. 2021
Источник: github
Github: Прошло ревью
CVSS3: 9.8

Описание

Unaligned memory access in rand_core

Impact

Affected versions of this crate violated alignment when casting byte slices to integer slices, resulting in undefined behavior. rand_core::BlockRng::next_u64 and rand_core::BlockRng::fill_bytes are affected.

Patches

The flaw was corrected by Ralf Jung and Diggory Hardy for rand_core >= 0.4.2.

Workarounds

None.

References

See Rand's changelog.

For more information

If you have any questions or comments about this advisory, open an issue in the Rand repository.

Пакеты

Наименование

rand_core

rust
Затронутые версииВерсия исправления

>= 0.4.0, < 0.4.2

0.4.2

Наименование

rand_core

rust
Затронутые версииВерсия исправления

< 0.3.1

0.3.1

EPSS

Процентиль: 67%
0.00544
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-704

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 5 лет назад

An issue was discovered in the rand_core crate before 0.4.2 for Rust. Casting of byte slices to integer slices mishandles alignment constraints.

CVSS3: 9.8
nvd
больше 5 лет назад

An issue was discovered in the rand_core crate before 0.4.2 for Rust. Casting of byte slices to integer slices mishandles alignment constraints.

CVSS3: 9.8
msrc
больше 1 года назад

Описание отсутствует

CVSS3: 9.8
debian
больше 5 лет назад

An issue was discovered in the rand_core crate before 0.4.2 for Rust. ...

EPSS

Процентиль: 67%
0.00544
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-704