We found results for “”
WS-2019-0116
Good to know:
Date: May 7, 2019
In slice-deque before 0.2.0, a bug in SliceDeque::move_head_unchecked allows an attacker that controls controls both element insertion and removal to corrupt the deque, such that reading elements from it would read bytes corresponding to other elements in the deque.
Language: RUST
Severity Score
Severity Score
Weakness Type (CWE)
Out-of-bounds Read
CWE-125Top Fix
CVSS v3.1
Base Score: |
|
---|---|
Attack Vector (AV): | LOCAL |
Attack Complexity (AC): | HIGH |
Privileges Required (PR): | NONE |
User Interaction (UI): | NONE |
Scope (S): | UNCHANGED |
Confidentiality (C): | NONE |
Integrity (I): | NONE |
Availability (A): | HIGH |