CVE Vulnerabilities

CVE-2020-25576

Incorrect Type Conversion or Cast

Published: Sep 14, 2020 | Modified: Sep 22, 2020
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

An issue was discovered in the rand_core crate before 0.4.2 for Rust. Casting of byte slices to integer slices mishandles alignment constraints.

Weakness

The product does not correctly convert an object, resource, or structure from one type to a different type.

Affected Software

Name Vendor Start Version End Version
Rand Rand_project * 0.4.2 (excluding)
Rust-rand-core Ubuntu trusty *
Rust-rand-core Ubuntu upstream *
Rust-rand-core-0.2 Ubuntu trusty *
Rust-rand-core-0.3 Ubuntu groovy *
Rust-rand-core-0.3 Ubuntu hirsute *
Rust-rand-core-0.3 Ubuntu impish *
Rust-rand-core-0.3 Ubuntu trusty *

References