GHSA-vqx7-pw4r-29rr

Suggest an improvement
Source
https://github.com/advisories/GHSA-vqx7-pw4r-29rr
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/08/GHSA-vqx7-pw4r-29rr/GHSA-vqx7-pw4r-29rr.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-vqx7-pw4r-29rr
Aliases
Published
2021-08-25T20:47:13Z
Modified
2023-11-08T04:03:36.095714Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
Out of bounds read in bumpalo
Details

An issue was discovered in the bumpalo crate before 3.2.1 for Rust. The realloc feature allows the reading of unknown memory. Attackers can potentially read cryptographic keys.

Database specific
{
    "nvd_published_at": null,
    "github_reviewed_at": "2021-08-19T21:18:29Z",
    "severity": "HIGH",
    "github_reviewed": true,
    "cwe_ids": [
        "CWE-125"
    ]
}
References

Affected packages

crates.io / bumpalo

Package

Affected ranges

Type
SEMVER
Events
Introduced
3.0.0
Fixed
3.2.1