CVE-2020-35901: Use After Free
Published Dec 31, 2020
·Updated
An issue was discovered in the actix-http crate before 2.0.0-alpha.1 for Rust. There is a use-after-free in BodyStream.
Affected Software
1 affected component
actix Actix-http Rust<=1.0.1
Remediation
Patch Available
Event History
Dec 31, 2020
CVE Published
via MITRE·08:22 AM
Data Sourced
via MITRE·08:22 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-35901?
CVE-2020-35901 has a medium severity due to the potential for denial of service from the use-after-free issue.
2
How do I fix CVE-2020-35901?
To fix CVE-2020-35901, update the actix-http crate to version 2.0.0-alpha.1 or later.
3
What is the impact of CVE-2020-35901?
The impact of CVE-2020-35901 is a potential crash or unexpected behavior in applications using the vulnerable version of actix-http.
4
Which versions are vulnerable to CVE-2020-35901?
Versions of actix-http before 2.0.0-alpha.1 are vulnerable to CVE-2020-35901.
5
Is there a public exploit for CVE-2020-35901?
As of now, there are no known public exploits for CVE-2020-35901.