An issue was discovered in the bumpalo crate before 3.2.1 for Rust. The realloc feature allows the reading of unknown memory. Attackers can potentially read cryptographic keys.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-1902 | An issue was discovered in the bumpalo crate before 3.2.1 for Rust. The realloc feature allows the reading of unknown memory. Attackers can potentially read cryptographic keys. |
Github GHSA |
GHSA-vqx7-pw4r-29rr | Out of bounds read in bumpalo |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://rustsec.org/advisories/RUSTSEC-2020-0006.html |
|
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T17:16:12.545Z
Reserved: 2020-12-31T00:00:00.000Z
Link: CVE-2020-35861
No data.
Status : Modified
Published: 2020-12-31T10:15:14.987
Modified: 2024-11-21T05:28:20.343
Link: CVE-2020-35861
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA