HIGH
An issue was discovered in the sized-chunks crate through 0.6.2 for Rust
Published Sep 19, 2020
7.5
HIGHCVSS 3.1
EPSS 2.90%
Description
An issue was discovered in the sized-chunks crate through 0.6.2 for Rust. In the Chunk implementation, the array size is not checked when constructed with pair().
Affected products
No data.
- ≤ 0.6.2
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (7)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2021-1805 Advisory
- https://github.com/advisories/GHSA-mp6f-p9gp-vpj9 Advisory
- https://github.com/bodil/sized-chunks/commit/3ae48bd463c1af41c24b96b84079946f51f51e3c
- https://github.com/bodil/sized-chunks/commit/99e593c3037438db478256a1f3101371a69cbd3f
- https://github.com/bodil/sized-chunks/issues/11 ExploitPatchThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-25792
- https://rustsec.org/advisories/RUSTSEC-2020-0041.html Third Party Advisory
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Sep 19, 2020
Updated May 5, 2025
Reserved Sep 19, 2020
Link CVE-2020-25792
CISA Vulnrichment
Updated Apr 23, 2025
Red Hat
No data
GitHub
Link GHSA-MP6F-P9GP-VPJ9