Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w3g5-2848-2v8r

Опубликовано: 25 авг. 2021
Источник: github
Github: Прошло ревью
CVSS3: 5.9

Описание

Data races in generator

The Generator type is an iterable which uses a generator function that yields values. In affected versions of the crate, the provided function yielding values had no Send bounds despite the Generator itself implementing Send.

The generator function lacking a Send bound means that types that are dangerous to send across threads such as Rc could be sent as part of a generator, potentially leading to data races.

This flaw was fixed in commit f7d120a3b by enforcing that the generator function be bound by Send.

Пакеты

Наименование

generator

rust
Затронутые версииВерсия исправления

< 0.7.0

0.7.0

EPSS

Процентиль: 51%
0.0028
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-362

Связанные уязвимости

CVSS3: 5.9
ubuntu
больше 4 лет назад

An issue was discovered in the generator crate before 0.7.0 for Rust. It does not ensure that a function (for yielding values) has Send bounds.

CVSS3: 5.9
nvd
больше 4 лет назад

An issue was discovered in the generator crate before 0.7.0 for Rust. It does not ensure that a function (for yielding values) has Send bounds.

CVSS3: 5.9
debian
больше 4 лет назад

An issue was discovered in the generator crate before 0.7.0 for Rust. ...

CVSS3: 5.9
fstec
больше 4 лет назад

Уязвимость библиотеки генератора стека языка Rust Generator-rs, связанная с некорректным преобразованием типа данных, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 51%
0.0028
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-362