RUSTSEC-2020-0029
Dashboard / Vulnerabilities / RUSTSEC-2020-0029
RUSTSEC-2020-0029
Summary: Allows viewing and modifying arbitrary structs as bytes
Details: Affected versions of rgb crate allow viewing and modifying data of any type `T` wrapped in `RGB<T>` as bytes, and do not correctly constrain `RGB<T>` and other wrapper structures to the types for which it is safe to do so. Safety violation possible for a type wrapped in `RGB<T>` and similar wrapper structures: * If `T` contains padding, viewing it as bytes may lead to exposure of contents of uninitialized memory. * If `T` contains a pointer, modifying it as bytes may lead to dereferencing of arbitrary pointers. * Any safety and/or validity invariants for `T` may be violated. The issue was resolved by requiring all types wrapped in structures provided by RGB crate to implement an unsafe marker trait.
References: https://crates.io/crates/rgb, https://rustsec.org/advisories/RUSTSEC-2020-0029.html, https://github.com/kornelski/rust-rgb/issues/35
Affected packages
Package
Name: rgb
Purl: pkg:cargo/rgb
Affected ranges
Type: SEMVER
Events:
