Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rh89-x75f-rh3c

Опубликовано: 25 авг. 2021
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Exposure of uninitialized memory in memoffset

Affected versions of this crate caused traps and/or memory unsafety by zero-initializing references. They also could lead to uninitialized memory being dropped if the field for which the offset is requested was behind a deref coercion, and that deref coercion caused a panic. The flaw was corrected by using MaybeUninit.

Пакеты

Наименование

memoffset

rust
Затронутые версииВерсия исправления

< 0.5.0

0.5.0

EPSS

Процентиль: 51%
0.00285
Низкий

7.5 High

CVSS3

Дефекты

CWE-908

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 6 лет назад

An issue was discovered in the memoffset crate before 0.5.0 for Rust. offset_of and span_of can cause exposure of uninitialized memory.

CVSS3: 7.5
nvd
больше 6 лет назад

An issue was discovered in the memoffset crate before 0.5.0 for Rust. offset_of and span_of can cause exposure of uninitialized memory.

CVSS3: 7.5
debian
больше 6 лет назад

An issue was discovered in the memoffset crate before 0.5.0 for Rust. ...

EPSS

Процентиль: 51%
0.00285
Низкий

7.5 High

CVSS3

Дефекты

CWE-908