First published: Thu Dec 31 2020(Updated: )
An issue was discovered in the socket2 crate before 0.3.16 for Rust. It has false expectations about the std::net::SocketAddr memory representation.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Rust-lang Socket2 | <0.3.16 | |
rust/net2 | <0.2.36 | 0.2.36 |
rust/socket2 | <0.3.16 | 0.3.16 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-35920 is an issue discovered in the socket2 crate before 0.3.16 for Rust.
CVE-2020-35920 could lead to unexpected behavior and potential security vulnerabilities in applications using the affected socket2 crate.
To mitigate the vulnerability in CVE-2020-35920, update your Rust projects to use version 0.3.16 or later of the socket2 crate.
You can find more information about CVE-2020-35920 in the advisory at https://rustsec.org/advisories/RUSTSEC-2020-0079.html.
CVE-2020-35920 has a severity rating of medium, with a CVSS score of 5.5.