GHSA-w7j2-35mf-95p7

    Dashboard / Vulnerabilities / GHSA-w7j2-35mf-95p7

    GHSA-w7j2-35mf-95p7

    Published: 25 Aug 2021Last Modified: 8 Nov 2023

    Summary: Incorrect check on buffer length in rand_core

    Details: An issue was discovered in the rand_core crate before 0.6.2 for Rust. Because `read_u32_into` and `read_u64_into` mishandle certain buffer-length checks, a random number generator may be seeded with too little data. The vulnerability was introduced in v0.6.0. The advisory doesn't apply to earlier minor version numbers. Because read_u32_into and read_u64_into mishandle certain buffer-length checks, a random number generator may be seeded with too little data.

    Affected packages

    Package

    Name: rand_core

    Purl: pkg:cargo/rand_core

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0.6.0
    Fixed -0.6.2

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-w7j2-35mf-95p7 | CVE-DB