An issue was discovered in the heapless crate before 0.6.1 for Rust. The IntoIter Clone implementation clones an entire underlying Vec without considering whether it has already been partially consumed.
References
| Link | Resource |
|---|---|
| https://raw.githubusercontent.com/rustsec/advisory-db/main/crates/heapless/RUSTSEC-2020-0145.md | Third Party Advisory |
| https://rustsec.org/advisories/RUSTSEC-2020-0145.html | Exploit Issue Tracking Patch Third Party Advisory |
| https://raw.githubusercontent.com/rustsec/advisory-db/main/crates/heapless/RUSTSEC-2020-0145.md | Third Party Advisory |
| https://rustsec.org/advisories/RUSTSEC-2020-0145.html | Exploit Issue Tracking Patch Third Party Advisory |
Configurations
History
No history.
Information
Published : 2021-08-08 06:15
Updated : 2024-11-21 05:29
NVD link : CVE-2020-36464
Mitre link : CVE-2020-36464
CVE.ORG link : CVE-2020-36464
JSON object : View
Products Affected
heapless_project
- heapless
CWE
CWE-416
Use After Free
