ZeroHour

CVE-2020-25016

PoC
CVSS 3.1
9.1 critical
EPSS
2%p74
Published
()
Modified
Description

A safety violation was discovered in the rgb crate before 0.8.20 for Rust, leading to (for example) dereferencing of arbitrary pointers or disclosure of uninitialized memory. This occurs because structs can be treated as bytes for read and write operations.

Vendors
rgb-rust project
Products
rgb-rust
Weakness
CWE-119, CWE-843
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.