CVE-2020-35908: Medium severity rust-lang future-utils vulnerability
Published Dec 31, 2020
·Updated
An issue was discovered in the futures-util crate before 0.3.2 for Rust. FuturesUnordered can lead to data corruption because Sync is mishandled.
Affected Software
1 affected component
rust-lang Future-utils<0.3.2
Event History
Dec 31, 2020
CVE Published
via MITRE·08:20 AM
Data Sourced
via MITRE·08:20 AM
Description
Frequently Asked Questions
1
What is CVE-2020-35908?
CVE-2020-35908 is a vulnerability in the futures-util crate before 0.3.2 for Rust that can lead to data corruption due to mishandling of Sync.
2
What software is affected by CVE-2020-35908?
The affected software is Rust-lang Future-utils version up to exclusive 0.3.2.
3
What is the severity of CVE-2020-35908?
CVE-2020-35908 has a severity level of medium with a CVSS score of 5.5.
4
How can I fix CVE-2020-35908?
To fix CVE-2020-35908, update the futures-util crate to version 0.3.2 or later.
5
Where can I find more information about CVE-2020-35908?
You can find more information about CVE-2020-35908 at https://rustsec.org/advisories/RUSTSEC-2020-0062.html.