RUSTSEC-2019-0037

Compiler optimisation for next_with_timeout in pnet::transport::IcmpTransportChannelIterator flaws to SEGFAULT

Issued
Package
pnet (crates.io)
Type
Vulnerability
Categories
  • memory-corruption
Details
https://github.com/libpnet/libpnet/issues/449
CVSS
CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
Patched
  • >=0.27.2
Keywords
  • segfault
Affected Functions
Version
pnet::transport::IcmpTransportChannelIterator
  • <0.27.2

Description

Affected versions of this crate were optimized out by compiler, which caused dereference of uninitialized file descriptor which caused segfault.

More