CVE-2019-12083
published 2019-05-13CVE-2019-12083: The Rust Programming Language Standard Library 1.34.x before 1.34.2 contains a stabilized method which, if overridden, can violate Rust's safety guarantees and…
PriorityP342high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
EPSS
2.22%
80.7th percentile
The Rust Programming Language Standard Library 1.34.x before 1.34.2 contains a stabilized method which, if overridden, can violate Rust's safety guarantees and cause memory unsafety. If the `Error::type_id` method is overridden then any type can be safely cast to any other type, causing memory safety vulnerabilities in safe code (e.g., out-of-bounds write or read). Code that does not manually implement Error::type_id is unaffected.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | rustc | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| opensuse | leap | — | — |
| rust-lang | rust | >= 0 < 1.34.2-r0 | 1.34.2-r0 |
| rust-lang | rust | >= 0 < 1.34.2-r0 | 1.34.2-r0 |
| rust-lang | rust | >= 0 < 1.34.2-r0 | 1.34.2-r0 |
| rust-lang | rust | >= 0 < 1.34.2-r0 | 1.34.2-r0 |
| rust-lang | rust | >= 0 < 1.34.2-r0 | 1.34.2-r0 |
| rust-lang | rust | >= 1.34.0 < 1.34.2 | 1.34.2 |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.1HIGH
vendor_debian8.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-vc89-vpx6-fmpm: The Rust Programming Language Standard Library 1
ghsa_unreviewed·2022-05-24
CVE-2019-12083 [HIGH] CWE-125 GHSA-vc89-vpx6-fmpm: The Rust Programming Language Standard Library 1
The Rust Programming Language Standard Library 1.34.x before 1.34.2 contains a stabilized method which, if overridden, can violate Rust's safety guarantees and cause memory unsafety. If the `Error::type_id` method is overridden then any type can be safely cast to any other type, causing memory safety vulnerabilities in safe code (e.g., out-of-bounds write or read). Code that does not manually implement Error::type_id is unaffected.
OSV
CVE-2019-12083: The Rust Programming Language Standard Library 1
osv·2019-05-13·CVSS 8.1
CVE-2019-12083 [HIGH] CVE-2019-12083: The Rust Programming Language Standard Library 1
The Rust Programming Language Standard Library 1.34.x before 1.34.2 contains a stabilized method which, if overridden, can violate Rust's safety guarantees and cause memory unsafety. If the `Error::type_id` method is overridden then any type can be safely cast to any other type, causing memory safety vulnerabilities in safe code (e.g., out-of-bounds write or read). Code that does not manually implement Error::type_id is unaffected.
Debian
CVE-2019-12083: rustc - The Rust Programming Language Standard Library 1.34.x before 1.34.2 contains a s...
vendor_debian·2019·CVSS 8.1
CVE-2019-12083 [HIGH] CVE-2019-12083: rustc - The Rust Programming Language Standard Library 1.34.x before 1.34.2 contains a s...
The Rust Programming Language Standard Library 1.34.x before 1.34.2 contains a stabilized method which, if overridden, can violate Rust's safety guarantees and cause memory unsafety. If the `Error::type_id` method is overridden then any type can be safely cast to any other type, causing memory safety vulnerabilities in safe code (e.g., out-of-bounds write or read). Code that does not manually implement Error::type_id is unaffected.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-12083 rust: overriden stabilized method `Error::type_id` can violate Rust's safety guarantees leading to out-of-bounds write or read [fedora-30]
bugzilla·2019-05-14·CVSS 8.1
CVE-2019-12083 [HIGH] CVE-2019-12083 rust: overriden stabilized method `Error::type_id` can violate Rust's safety guarantees leading to out-of-bounds write or read [fedora-30]
CVE-2019-12083 rust: overriden stabilized method `Error::type_id` can violate Rust's safety guarantees leading to out-of-bounds write or read [fedora-30]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-30.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
f
Bugzilla
CVE-2019-12083 rust: overriden stabilized method `Error::type_id` can violate Rust's safety guarantees leading to out-of-bounds write or read [epel-7]
bugzilla·2019-05-14·CVSS 8.1
CVE-2019-12083 [HIGH] CVE-2019-12083 rust: overriden stabilized method `Error::type_id` can violate Rust's safety guarantees leading to out-of-bounds write or read [epel-7]
CVE-2019-12083 rust: overriden stabilized method `Error::type_id` can violate Rust's safety guarantees leading to out-of-bounds write or read [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-7.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg
Bugzilla
CVE-2019-12083 rust: overriden stabilized method `Error::type_id` can violate Rust's safety guarantees leading to out-of-bounds write or read [fedora-29]
bugzilla·2019-05-14·CVSS 8.1
CVE-2019-12083 [HIGH] CVE-2019-12083 rust: overriden stabilized method `Error::type_id` can violate Rust's safety guarantees leading to out-of-bounds write or read [fedora-29]
CVE-2019-12083 rust: overriden stabilized method `Error::type_id` can violate Rust's safety guarantees leading to out-of-bounds write or read [fedora-29]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-29.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
f
Bugzilla
CVE-2019-12083 rust: overriden stabilized method `Error::type_id` can violate Rust's safety guarantees leading to out-of-bounds write or read
bugzilla·2019-05-14·CVSS 8.1
CVE-2019-12083 [HIGH] CVE-2019-12083 rust: overriden stabilized method `Error::type_id` can violate Rust's safety guarantees leading to out-of-bounds write or read
CVE-2019-12083 rust: overriden stabilized method `Error::type_id` can violate Rust's safety guarantees leading to out-of-bounds write or read
The Rust Programming Language Standard Library 1.34.x before 1.34.2 contains a stabilized method which, if overridden, can violate Rust's safety guarantees and cause memory unsafety. If the `Error::type_id` method is overridden then any type can be safely cast to any other type, causing memory safety vulnerabilities in safe code (e.g., out-of-bounds write or read). Code that does not manually implement Error::type_id is unaffected.
External References:
https://blog.rust-lang.org/2019/05/13/Security-advisory.html
Discussion:
Created rust tracking bugs for this issue:
Affects: epel-7 [bug 1709712]
Affects: fedora-29 [bug 1709710]
Affects: fedora-3
arXiv
Memory-Safety Challenge Considered Solved? An In-Depth Study with All Rust CVEs
arxiv_fulltext·2021-02-25
Memory-Safety Challenge Considered Solved? An In-Depth Study with All Rust CVEs
Memory-Safety Challenge Considered Solved? An In-Depth Study with All Rust CVEs
Hui Xu
School of Computer Science, Fudan University
Zhuangbin Chen
Dept. of CSE, The Chinese University of Hong Kong
Mingshen Sun
Baidu Security
Yangfan Zhou
School of Computer Science, Fudan University
Michael R. Lyu
Dept. of CSE, The Chinese University of Hong Kong
## Abstract
Rust is an emerging programing language that aims at preventing memory-safety bugs without sacrificing much efficiency. The claimed property is very attractive to developers, and many projects start using the language. However, can Rust achieve the memory-safety promise? This paper studies the question by surveying 186 real-world bug reports collected from several origins which contain all existing Rust CVEs (common vulnerab
http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00076.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-10/msg00006.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-10/msg00031.htmlhttps://blog.rust-lang.org/2019/05/13/Security-advisory.htmlhttps://groups.google.com/forum/#%21topic/rustlang-security-announcements/aZabeCMUv70https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HG47HYH3AQTUMBUMX3S3G5DNAY4CBW6N/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/K6T4BNA5KQYJRIKIGGBOGBMR7TRXPHLR/http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00076.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-10/msg00006.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-10/msg00031.htmlhttps://blog.rust-lang.org/2019/05/13/Security-advisory.htmlhttps://groups.google.com/forum/#%21topic/rustlang-security-announcements/aZabeCMUv70https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HG47HYH3AQTUMBUMX3S3G5DNAY4CBW6N/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/K6T4BNA5KQYJRIKIGGBOGBMR7TRXPHLR/
2019-05-13
Published