CVE Vulnerabilities

CVE-2018-20992

Use of Uninitialized Resource

Published: Aug 26, 2019 | Modified: Aug 24, 2020
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

An issue was discovered in the claxon crate before 0.4.1 for Rust. Uninitialized memory can be exposed because certain decode buffer sizes are mishandled.

Weakness

The product uses or accesses a resource that has not been initialized.

Affected Software

Name Vendor Start Version End Version
Claxon Claxon_project 0.2.0 (including) 0.3.1 (including)
Claxon Claxon_project 0.4.0 (including) 0.4.0 (including)

Potential Mitigations

References