Vulnerabilities > CVE-2019-12083 - Out-of-bounds Write vulnerability in multiple products
Attack vector
NETWORK Attack complexity
HIGH Privileges required
NONE Confidentiality impact
HIGH Integrity impact
HIGH Availability impact
HIGH Summary
The Rust Programming Language Standard Library 1.34.x before 1.34.2 contains a stabilized method which, if overridden, can violate Rust's safety guarantees and cause memory unsafety. If the `Error::type_id` method is overridden then any type can be safely cast to any other type, causing memory safety vulnerabilities in safe code (e.g., out-of-bounds write or read). Code that does not manually implement Error::type_id is unaffected.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 2 | |
OS | 2 | |
OS | 1 |
Common Weakness Enumeration (CWE)
Nessus
NASL family SuSE Local Security Checks NASL id OPENSUSE-2019-2244.NASL description This update for rust fixes the following issues : Rust was updated to version 1.36.0. Security issues fixed : - CVE-2019-12083: a standard method can be overridden violating Rust last seen 2020-06-01 modified 2020-06-02 plugin id 129579 published 2019-10-04 reporter This script is Copyright (C) 2019 and is owned by Tenable, Inc. or an Affiliate thereof. source https://www.tenable.com/plugins/nessus/129579 title openSUSE Security Update : rust (openSUSE-2019-2244) NASL family SuSE Local Security Checks NASL id OPENSUSE-2019-2203.NASL description This update for rust fixes the following issues : Rust was updated to version 1.36.0. Security issues fixed : - CVE-2019-12083: a standard method can be overridden violating Rust last seen 2020-06-01 modified 2020-06-02 plugin id 129455 published 2019-09-30 reporter This script is Copyright (C) 2019 and is owned by Tenable, Inc. or an Affiliate thereof. source https://www.tenable.com/plugins/nessus/129455 title openSUSE Security Update : rust (openSUSE-2019-2203) NASL family SuSE Local Security Checks NASL id SUSE_SU-2019-2439-1.NASL description This update for rust fixes the following issues : Rust was updated to version 1.36.0. Security issues fixed : CVE-2019-12083: a standard method can be overridden violating Rust last seen 2020-06-01 modified 2020-06-02 plugin id 129287 published 2019-09-24 reporter This script is Copyright (C) 2019 and is owned by Tenable, Inc. or an Affiliate thereof. source https://www.tenable.com/plugins/nessus/129287 title SUSE SLED15 / SLES15 Security Update : rust (SUSE-SU-2019:2439-1) NASL family SuSE Local Security Checks NASL id OPENSUSE-2019-2201.NASL description This update for rust fixes the following issues : Rust was updated to version 1.36.0. Security issues fixed : - CVE-2019-12083: a standard method can be overridden violating Rust last seen 2020-06-01 modified 2020-06-02 plugin id 129400 published 2019-09-27 reporter This script is Copyright (C) 2019 and is owned by Tenable, Inc. or an Affiliate thereof. source https://www.tenable.com/plugins/nessus/129400 title openSUSE Security Update : rust (openSUSE-2019-2201) NASL family FreeBSD Local Security Checks NASL id FREEBSD_PKG_3752837976A811E9A4FD00012E582166.NASL description Sean McArthur reports : The Rust Programming Language Standard Library 1.34.x before 1.34.2 contains a stabilized method which, if overridden, can violate Rust last seen 2020-06-01 modified 2020-06-02 plugin id 125098 published 2019-05-15 reporter This script is Copyright (C) 2019-2020 and is owned by Tenable, Inc. or an Affiliate thereof. source https://www.tenable.com/plugins/nessus/125098 title FreeBSD : Rust -- violation of Rust's safety guarantees (37528379-76a8-11e9-a4fd-00012e582166) NASL family Fedora Local Security Checks NASL id FEDORA_2019-E39D4910C6.NASL description Security fix for CVE-2019-12083 Note that Tenable Network Security has extracted the preceding description block directly from the Fedora update system website. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues. last seen 2020-06-01 modified 2020-06-02 plugin id 125433 published 2019-05-28 reporter This script is Copyright (C) 2019-2020 and is owned by Tenable, Inc. or an Affiliate thereof. source https://www.tenable.com/plugins/nessus/125433 title Fedora 30 : rust (2019-e39d4910c6) NASL family SuSE Local Security Checks NASL id SUSE_SU-2019-2755-1.NASL description This update for rust fixes the following issues : Rust was updated to version 1.36.0. Security issues fixed : CVE-2019-12083: a standard method can be overridden violating Rust last seen 2020-06-01 modified 2020-06-02 plugin id 130198 published 2019-10-24 reporter This script is Copyright (C) 2019 and is owned by Tenable, Inc. or an Affiliate thereof. source https://www.tenable.com/plugins/nessus/130198 title SUSE SLED15 / SLES15 Security Update : rust (SUSE-SU-2019:2755-1) NASL family Fedora Local Security Checks NASL id FEDORA_2019-F76F0E11B3.NASL description Security fix for CVE-2019-12083 Note that Tenable Network Security has extracted the preceding description block directly from the Fedora update system website. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues. last seen 2020-06-01 modified 2020-06-02 plugin id 125435 published 2019-05-28 reporter This script is Copyright (C) 2019-2020 and is owned by Tenable, Inc. or an Affiliate thereof. source https://www.tenable.com/plugins/nessus/125435 title Fedora 29 : rust (2019-f76f0e11b3) NASL family SuSE Local Security Checks NASL id OPENSUSE-2019-2294.NASL description This update for rust fixes the following issues : Rust was updated to version 1.36.0. Security issues fixed : - CVE-2019-12083: a standard method can be overridden violating Rust last seen 2020-06-01 modified 2020-06-02 plugin id 129743 published 2019-10-09 reporter This script is Copyright (C) 2019 and is owned by Tenable, Inc. or an Affiliate thereof. source https://www.tenable.com/plugins/nessus/129743 title openSUSE Security Update : rust (openSUSE-2019-2294)
References
- https://blog.rust-lang.org/2019/05/13/Security-advisory.html
- http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00076.html
- http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00006.html
- http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00031.html
- https://groups.google.com/forum/#%21topic/rustlang-security-announcements/aZabeCMUv70
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/K6T4BNA5KQYJRIKIGGBOGBMR7TRXPHLR/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HG47HYH3AQTUMBUMX3S3G5DNAY4CBW6N/