Lucene search

K
cveMitreCVE-2018-1000810
HistoryOct 08, 2018 - 3:29 p.m.

CVE-2018-1000810

2018-10-0815:29:01
CWE-190
mitre
web.nvd.nist.gov
35
rust
programming language
standard library
vulnerability
cwe-680
integer overflow
buffer overflow
nvd
cve-2018-1000810

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.5

Confidence

High

EPSS

0.004

Percentile

72.9%

The Rust Programming Language Standard Library version 1.29.0, 1.28.0, 1.27.2, 1.27.1, 127.0, 126.2, 126.1, 126.0 contains a CWE-680: Integer Overflow to Buffer Overflow vulnerability in standard library that can result in buffer overflow. This attack appear to be exploitable via str::repeat, passed a large number, can overflow an internal buffer. This vulnerability appears to have been fixed in 1.29.1.

Affected configurations

Nvd
Node
rust-langrustMatch1.26.0
OR
rust-langrustMatch1.26.1
OR
rust-langrustMatch1.26.2
OR
rust-langrustMatch1.27.0
OR
rust-langrustMatch1.27.1
OR
rust-langrustMatch1.27.2
OR
rust-langrustMatch1.28.0
OR
rust-langrustMatch1.29.0
VendorProductVersionCPE
rust-langrust1.26.0cpe:2.3:a:rust-lang:rust:1.26.0:*:*:*:*:*:*:*
rust-langrust1.26.1cpe:2.3:a:rust-lang:rust:1.26.1:*:*:*:*:*:*:*
rust-langrust1.26.2cpe:2.3:a:rust-lang:rust:1.26.2:*:*:*:*:*:*:*
rust-langrust1.27.0cpe:2.3:a:rust-lang:rust:1.27.0:*:*:*:*:*:*:*
rust-langrust1.27.1cpe:2.3:a:rust-lang:rust:1.27.1:*:*:*:*:*:*:*
rust-langrust1.27.2cpe:2.3:a:rust-lang:rust:1.27.2:*:*:*:*:*:*:*
rust-langrust1.28.0cpe:2.3:a:rust-lang:rust:1.28.0:*:*:*:*:*:*:*
rust-langrust1.29.0cpe:2.3:a:rust-lang:rust:1.29.0:*:*:*:*:*:*:*

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.5

Confidence

High

EPSS

0.004

Percentile

72.9%