#VU36555 Integer overflow in Rust Programming Language - CVE-2018-1000810
Published: October 8, 2018 / Updated: August 8, 2020
Rust Programming Language
Rust Team
Description
The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
The Rust Programming Language Standard Library version 1.29.0, 1.28.0, 1.27.2, 1.27.1, 127.0, 126.2, 126.1, 126.0 contains a CWE-680: Integer Overflow to Buffer Overflow vulnerability in standard library that can result in buffer overflow. This attack appear to be exploitable via str::repeat, passed a large number, can overflow an internal buffer. This vulnerability appears to have been fixed in 1.29.1.