CVE-2020-36211: High severity devolutions gfwx vulnerability
Published Jan 22, 2021
·Updated
An issue was discovered in the gfwx crate before 0.3.0 for Rust. Because ImageChunkMut does not have bounds on its Send trait or Sync trait, a data race and memory corruption can occur.
Affected Software
1 affected component
Devolutions Gfwx Rust<0.3.0
Event History
Jan 22, 2021
CVE Published
via MITRE·09:05 AM
Data Sourced
via MITRE·09:05 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2020-36211.
2
What is the severity of the vulnerability CVE-2020-36211?
The severity of the vulnerability CVE-2020-36211 is high with a severity value of 7.
3
What software is affected by CVE-2020-36211?
The Devolutions Gfwx software version up to exclusive 0.3.0 is affected by CVE-2020-36211.
4
What is the issue with the gfwx crate before version 0.3.0 for Rust?
The issue with the gfwx crate before version 0.3.0 for Rust is that the ImageChunkMut does not have bounds on its Send trait or Sync trait, which can lead to a data race and memory corruption.
5
Where can I find more information about CVE-2020-36211?
You can find more information about CVE-2020-36211 at https://rustsec.org/advisories/RUSTSEC-2020-0104.html.