Data Corruption Vulnerability in futures-util Crate for Rust
CVE-2020-35908
5.5MEDIUM
Summary
A vulnerability exists in the futures-util crate, where the FuturesUnordered structure mishandles synchronization (Sync). This flaw can potentially lead to data corruption when utilized improperly, affecting the reliability of applications relying on this crate. Users of futures-util versions prior to 0.3.2 should take caution and consider upgrading to mitigate the risk.
References
CVSS V3.1
Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved