VulnerabilityModified
CVE-2018-20992
Uninitialized memory can be exposed because certain decode buffer sizes are mishandled.
MEDIUM 6.5EPSS 1.37%
Does this matter?
Lower severity and a low EPSS score (1.37%). Track it; it rarely justifies an emergency change on its own.
Description
An issue was discovered in the claxon crate before 0.4.1 for Rust. Uninitialized memory can be exposed because certain decode buffer sizes are mishandled.
- CVSS 3.0
- 6.5 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
- EPSS
- 1.37% probability · 70th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-908
- Affected
- claxon project/claxon
- Source
- cve@mitre.org
References
- https://rustsec.org/advisories/RUSTSEC-2018-0004.htmlPatch, Third Party Advisory
- https://rustsec.org/advisories/RUSTSEC-2018-0004.htmlPatch, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.