CVE-2020-36323

HIGH8.2EPSS 1.0%
發布日:2021/4/14修改日:2025/12/3
也稱為:ALPINE-CVE-2020-36323

描述

In the standard library in Rust before 1.52.0, there is an optimization for joining strings that can cause uninitialized bytes to be exposed (or the program to crash) if the borrowed string changes after its length is checked.

受影響套件(2)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1HIGH8.2CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H

參考連結(2)