GHSA-vqx7-pw4r-29rr

Suggest an improvement
Source
https://github.com/advisories/GHSA-vqx7-pw4r-29rr
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/08/GHSA-vqx7-pw4r-29rr/GHSA-vqx7-pw4r-29rr.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-vqx7-pw4r-29rr
Aliases
Published
2021-08-25T20:47:13Z
Modified
2023-11-08T04:03:36Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
Out of bounds read in bumpalo
Details

An issue was discovered in the bumpalo crate before 3.2.1 for Rust. The realloc feature allows the reading of unknown memory. Attackers can potentially read cryptographic keys.

Database specific
{
    "cwe_ids":  [
        "CWE-125"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2021-08-19T21:18:29Z",
    "nvd_published_at":  null,
    "severity":  "HIGH"
}
References

Affected packages

crates.io / bumpalo

Package

Name
bumpalo
View open source insights on deps.dev
Purl
pkg:cargo/bumpalo

Affected ranges

Type
SEMVER
Events
Introduced
3.0.0
Fixed
3.2.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/08/GHSA-vqx7-pw4r-29rr/GHSA-vqx7-pw4r-29rr.json"