Structs as Bytes: Arbitrary Pointer Dereferencing and Uninitialized Memory Disclosure in rgb crate (Rust)

Structs as Bytes: Arbitrary Pointer Dereferencing and Uninitialized Memory Disclosure in rgb crate (Rust)

CVE-2020-25016 · CRITICAL Severity

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

A safety violation was discovered in the rgb crate before 0.8.20 for Rust, leading to (for example) dereferencing of arbitrary pointers or disclosure of uninitialized memory. This occurs because structs can be treated as bytes for read and write operations.

Learn more about our Web Application Penetration Testing UK.