HistoryEditJSON (OSV)

RUSTSEC-2019-0037

Compiler optimisation for next_with_timeout in pnet::transport::IcmpTransportChannelIterator flaws to SEGFAULT

Reported
Issued
Package
pnet (crates.io)
Type
Vulnerability
Categories
Keywords
#segfault
Aliases
References
CVSS Score
6 MEDIUM
CVSS Details
Attack Vector
Local
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Unchanged
Confidentiality Impact
None
Integrity Impact
High
Availability Impact
High
CVSS Vector
CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
Patched
  • >=0.27.2
Affected Functions
Version
pnet::transport::IcmpTransportChannelIterator
  • <0.27.2

Description

Affected versions of this crate were optimized out by compiler, which caused dereference of uninitialized file descriptor which caused segfault.

Advisory available under CC0-1.0 license.