GHSA-m9m5-cg5h-r582
Dashboard / Vulnerabilities / GHSA-m9m5-cg5h-r582
GHSA-m9m5-cg5h-r582
Summary: Improper random number generation in nanorand
Details: In versions of nanorand prior to 0.5.1, RandomGen implementations for standard unsigned integers could fail to properly generate numbers, due to using bit-shifting to truncate a 64-bit number, rather than just an as conversion. This often manifested as RNGs returning nothing but 0, including the cryptographically secure ChaCha random number generator.
References: https://nvd.nist.gov/vuln/detail/CVE-2020-35926, https://github.com/Absolucy/nanorand-rs/commit/5ba218ac29df4786b002d7d12b47fa0c04a331f2, https://github.com/Absolucy/nanorand-rs, https://rustsec.org/advisories/RUSTSEC-2020-0089.html, https://twitter.com/aspenluxxxy/status/1336684692284772352
Affected packages
Package
Name: nanorand
Purl: pkg:cargo/nanorand
Affected ranges
Type: SEMVER
Events:
