Vulnerability Description
An issue was discovered in the heapless crate before 0.6.1 for Rust. The IntoIter Clone implementation clones an entire underlying Vec without considering whether it has already been partially consumed.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Heapless Project | Heapless | < 0.6.1 |
Related Weaknesses (CWE)
References
- https://raw.githubusercontent.com/rustsec/advisory-db/main/crates/heapless/RUSTSThird Party Advisory
- https://rustsec.org/advisories/RUSTSEC-2020-0145.htmlExploitIssue TrackingPatch
- https://raw.githubusercontent.com/rustsec/advisory-db/main/crates/heapless/RUSTSThird Party Advisory
- https://rustsec.org/advisories/RUSTSEC-2020-0145.htmlExploitIssue TrackingPatch
FAQ
What is CVE-2020-36464?
CVE-2020-36464 is a vulnerability with a CVSS score of 7.5 (HIGH). An issue was discovered in the heapless crate before 0.6.1 for Rust. The IntoIter Clone implementation clones an entire underlying Vec without considering whether it has already been partially consume...
How severe is CVE-2020-36464?
CVE-2020-36464 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-36464?
Check the references section above for vendor advisories and patch information. Affected products include: Heapless Project Heapless.