icon

We found results for “

WS-2020-0232

Good to know:

icon

Date: November 12, 2020

The crate 'image' was found vulnerable before version 0.23.12. A mutable reference to a struct was constructed by dereferencing a pointer obtained from slice::as_ptr. Instead, slice::as_mut_ptr should have been called on the mutable slice argument. The former performs an implicit reborrow as an immutable shared reference which does not allow writing through the derived pointer. There is no evidence for miscompilation, exploitable or otherwise, caused by this bug. Further investigation on Zulip suggests that the unoptimized generated LLVM IR does not contain any UB itself, effectively mitigating further effects.

Language: RUST

Severity Score

Severity Score

Weakness Type (CWE)

Access of Uninitialized Pointer

CWE-824

Top Fix

icon

Upgrade Version

Upgrade to version 0.23.12

Learn More

CVSS v3.1

Base Score:
Attack Vector (AV): LOCAL
Attack Complexity (AC): LOW
Privileges Required (PR): NONE
User Interaction (UI): REQUIRED
Scope (S): UNCHANGED
Confidentiality (C): NONE
Integrity (I): NONE
Availability (A): HIGH

Do you need more information?

Contact Us