Vulnerability Details CVE-2019-1010299
The Rust Programming Language Standard Library 1.18.0 and later is affected by: CWE-200: Information Exposure. The impact is: Contents of uninitialized memory could be printed to string or to log file. The component is: Debug trait implementation for std::collections::vec_deque::Iter. The attack vector is: The program needs to invoke debug printing for iterator over an empty VecDeque. The fixed version is: 1.30.0, nightly versions after commit b85e4cc8fadaabd41da5b9645c08c68b8f89908d.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 52.6%
CVSS Severity
CVSS v3 Score 5.3
CVSS v2 Score 5.0
Products affected by CVE-2019-1010299
-
cpe:2.3:a:rust-lang:rust:1.18.0
-
cpe:2.3:a:rust-lang:rust:1.19.0
-
cpe:2.3:a:rust-lang:rust:1.20.0
-
cpe:2.3:a:rust-lang:rust:1.21.0
-
cpe:2.3:a:rust-lang:rust:1.22.0
-
cpe:2.3:a:rust-lang:rust:1.22.1
-
cpe:2.3:a:rust-lang:rust:1.23.0
-
cpe:2.3:a:rust-lang:rust:1.24.0
-
cpe:2.3:a:rust-lang:rust:1.24.1
-
cpe:2.3:a:rust-lang:rust:1.25.0
-
cpe:2.3:a:rust-lang:rust:1.26.0
-
cpe:2.3:a:rust-lang:rust:1.26.1
-
cpe:2.3:a:rust-lang:rust:1.26.2
-
cpe:2.3:a:rust-lang:rust:1.27.0
-
cpe:2.3:a:rust-lang:rust:1.27.1
-
cpe:2.3:a:rust-lang:rust:1.27.2
-
cpe:2.3:a:rust-lang:rust:1.28.0
-
cpe:2.3:a:rust-lang:rust:1.29.0
-
cpe:2.3:a:rust-lang:rust:1.29.1
-
cpe:2.3:a:rust-lang:rust:1.29.2