CVE-2019-15554

Source
https://nvd.nist.gov/vuln/detail/CVE-2019-15554
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-15554.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2019-15554
Aliases
Published
2019-08-26T15:15:12Z
Modified
2024-09-18T01:00:22Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

An issue was discovered in the smallvec crate before 0.6.10 for Rust. There is memory corruption for certain grow attempts with less than the current capacity.

References

Affected packages

Debian:11 / rust-smallvec

Package

Name
rust-smallvec
Purl
pkg:deb/debian/rust-smallvec?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.6.10-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12 / rust-smallvec

Package

Name
rust-smallvec
Purl
pkg:deb/debian/rust-smallvec?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.6.10-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / rust-smallvec

Package

Name
rust-smallvec
Purl
pkg:deb/debian/rust-smallvec?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.6.10-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}