GHSA-mmc9-pwm7-qj5w
Dashboard / Vulnerabilities / GHSA-mmc9-pwm7-qj5w
GHSA-mmc9-pwm7-qj5w
Summary: Unaligned memory access in rand_core
Details: ### Impact Affected versions of this crate violated alignment when casting byte slices to integer slices, resulting in undefined behavior. `rand_core::BlockRng::next_u64` and `rand_core::BlockRng::fill_bytes` are affected. ### Patches The flaw was corrected by Ralf Jung and Diggory Hardy for `rand_core >= 0.4.2`. ### Workarounds None. ### References See [Rand's changelog](https://github.com/rust-random/rand/blob/master/rand_core/CHANGELOG.md#050---2019-06-06). ### For more information If you have any questions or comments about this advisory, [open an issue in the Rand repository](https://github.com/rust-random/rand/issues/new/choose).
References: https://github.com/rust-random/rand/security/advisories/GHSA-mmc9-pwm7-qj5w, https://github.com/rust-random/rand, https://github.com/rust-random/rand/blob/master/rand_core/CHANGELOG.md#050---2019-06-06, https://rustsec.org/advisories/RUSTSEC-2019-0035.html
Affected packages
Package
Name: rand_core
Purl: pkg:cargo/rand_core
Affected ranges
Type: SEMVER
Events:
