CVE-2020-35902: Use After Free
Published Dec 31, 2020
·Updated
An issue was discovered in the actix-codec crate before 0.3.0-beta.1 for Rust. There is a use-after-free in Framed.
Affected Software
2 affected componentsFixes available
actix Actix-codec Rust<=0.2.0
rust/actix-codec<0.3.0
0.3.0
Event History
Dec 31, 2020
CVE Published
via MITRE·08:22 AM
Data Sourced
via MITRE·08:22 AM
Description
Data Sourced
via NVD·09:15 AM
DescriptionSeverityWeaknessAffected Software
Aug 25, 2021
Advisory Published
via GitHub·08:49 PM
Frequently Asked Questions
1
What is the severity of CVE-2020-35902?
CVE-2020-35902 is classified as a medium severity vulnerability due to its potential for causing application crashes and instability.
2
How do I fix CVE-2020-35902?
To fix CVE-2020-35902, upgrade the actix-codec crate to version 0.3.0 or later.
3
What does the use-after-free vulnerability in CVE-2020-35902 affect?
CVE-2020-35902 affects the actix-codec crate in Rust, specifically leading to potential memory corruption issues.
4
Which versions of actix-codec are affected by CVE-2020-35902?
Versions of actix-codec prior to 0.3.0-beta.1 are affected by CVE-2020-35902.
5
Is CVE-2020-35902 related to application security?
Yes, CVE-2020-35902 poses a risk to application security by allowing for use-after-free conditions that could lead to exploitation.