9.1
CVSSv3

CVE-2020-25016

Published: 29/08/2020 Updated: 21/07/2021
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
CVSS v3 Base Score: 9.1 | Impact Score: 5.2 | Exploitability Score: 3.9
VMScore: 570
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N

Vulnerability Summary

A safety violation exists in the rgb crate prior to 0.8.20 for Rust, leading to (for example) dereferencing of arbitrary pointers or disclosure of uninitialized memory. This occurs because structs can be treated as bytes for read and write operations.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

rgb-rust project rgb-rust

Vendor Advisories

Debian Bug report logs - #969213 rust-rgb: CVE-2020-25016: RUSTSEC-2020-0029: Allows viewing and modifying arbitrary structs as bytes Package: src:rust-rgb; Maintainer for src:rust-rgb is Debian Rust Maintainers <pkg-rust-maintainers@alioth-listsdebiannet>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: ...