CVE Vulnerabilities

CVE-2018-20989

Integer Underflow (Wrap or Wraparound)

Published: Aug 26, 2019 | Modified: Nov 21, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
LOW

An issue was discovered in the untrusted crate before 0.6.2 for Rust. Error handling can trigger an integer underflow and panic.

Weakness

The product subtracts one value from another, such that the result is less than the minimum allowable integer value, which produces a value that is not equal to the correct result.

Affected Software

Name Vendor Start Version End Version
Untrusted Untrusted_project * 0.6.2 (excluding)
Rust-untrusted Ubuntu disco *
Rust-untrusted Ubuntu eoan *
Rust-untrusted Ubuntu groovy *
Rust-untrusted Ubuntu hirsute *
Rust-untrusted Ubuntu impish *
Rust-untrusted Ubuntu kinetic *
Rust-untrusted Ubuntu lunar *
Rust-untrusted Ubuntu mantic *
Rust-untrusted Ubuntu trusty *

References