GHSA-wfg4-322g-9vqv

    Dashboard / Vulnerabilities / GHSA-wfg4-322g-9vqv

    GHSA-wfg4-322g-9vqv

    Published: 21 Jun 2023Last Modified: 8 Nov 2023

    Summary: memoffset allows reading uninitialized memory

    Details: memoffset allows attempt of reading data from address `0` with arbitrary type. This behavior is an undefined behavior because address `0` to `std::mem::size_of<T>` may not have valid bit-pattern with `T`. Old implementation dereferences uninitialized memory obtained from `std::mem::align_of`. Older implementation prior to it allows using uninitialized data obtained from `std::mem::uninitialized` with arbitrary type then compute offset by taking the address of field-projection. This may also result in an undefined behavior for "father" that includes (directly or transitively) type that [does not allow to be uninitialized](https://doc.rust-lang.org/nightly/reference/behavior-considered-undefined.html). This flaw was corrected by using `std::ptr::addr_of` in <https://github.com/Gilnaa/memoffset/pull/50>.

    Affected packages

    Package

    Name: memoffset

    Purl: pkg:cargo/memoffset

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -0.6.2

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-wfg4-322g-9vqv | CVE-DB