HIGH
rust: Buffer Overflow vulnerability in std::collections::vec_deque::VecDeque::reserve() function
Published Aug 20, 2018
7.8
HIGHCVSS 3.0
EPSS 0.54%
Description
Rust Programming Language Rust standard library version Commit bfa0e1f58acf1c28d500c34ed258f09ae021893e and later; stable release 1.3.0 and later contains a Buffer Overflow vulnerability in std::collections::vec_deque::VecDeque::reserve() function that can result in Arbitrary code execution, but no proof-of-concept exploit is currently published.. This vulnerability appears to have been fixed in after commit fdfafb510b1a38f727e920dccbeeb638d39a8e60; stable release 1.22.0 and later.
Affected products
Remediation
No remediation recorded yet.
Weaknesses (1)
References (7)
- http://www.securityfocus.com/bid/105188 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- https://access.redhat.com/security/cve/CVE-2018-1000657 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1622249 Issue Tracking
- https://github.com/rust-lang/rust/commit/f71b37bc28326e272a37b938e835d4f99113eec2 x_refsource_CONFIRMPatchThird Party Advisory
- https://github.com/rust-lang/rust/issues/44800 x_refsource_CONFIRMIssue TrackingThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2018-1000657
- https://www.cve.org/CVERecord?id=CVE-2018-1000657
| Link | Providers | Tags |
|---|---|---|
| http://www.securityfocus.com/bid/105188 | vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry | |
| https://access.redhat.com/security/cve/CVE-2018-1000657 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1622249 | Issue Tracking | |
| https://github.com/rust-lang/rust/commit/f71b37bc28326e272a37b938e835d4f99113eec2 | x_refsource_CONFIRMPatchThird Party Advisory | |
| https://github.com/rust-lang/rust/issues/44800 | x_refsource_CONFIRMIssue TrackingThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2018-1000657 | ||
| https://www.cve.org/CVERecord?id=CVE-2018-1000657 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Aug 20, 2018
Updated Aug 5, 2024
Reserved Aug 16, 2018
Link CVE-2018-1000657
CISA Vulnrichment
Updated n/a