{"id":"GHSA-w7j2-35mf-95p7","summary":"Incorrect check on buffer length in rand_core","details":"An issue was discovered in the rand_core crate before 0.6.2 for Rust. Because `read_u32_into` and `read_u64_into` mishandle certain buffer-length checks, a random number generator may be seeded with too little data. The vulnerability was introduced in v0.6.0. The advisory doesn't apply to earlier minor version numbers.\n\nBecause read_u32_into and read_u64_into mishandle certain buffer-length checks, a random number generator may be seeded with too little data.","aliases":["CVE-2021-27378","RUSTSEC-2021-0023"],"modified":"2023-11-01T04:54:54.820398Z","published":"2021-08-25T20:52:16Z","database_specific":{"cwe_ids":["CWE-330"],"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2021-08-19T17:35:01Z","nvd_published_at":"2021-02-18T04:15:00Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-27378"},{"type":"WEB","url":"https://github.com/rust-random/rand/pull/1096"},{"type":"PACKAGE","url":"https://github.com/rust-random/rand"},{"type":"WEB","url":"https://github.com/rust-random/rand/compare/0.6.0...rand_core-0.6.2#diff-f41b3dfa5ce28f3bee390d327c50621e141cf3569921f8e9ca15ccfcf25263a9R19"},{"type":"WEB","url":"https://github.com/rust-random/rand/compare/0.6.0...rand_core-0.6.2#diff-f41b3dfa5ce28f3bee390d327c50621e141cf3569921f8e9ca15ccfcf25263a9R28"},{"type":"WEB","url":"https://rustsec.org/advisories/RUSTSEC-2021-0023.html"}],"affected":[{"package":{"name":"rand_core","ecosystem":"crates.io","purl":"pkg:cargo/rand_core"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0.6.0"},{"fixed":"0.6.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/08/GHSA-w7j2-35mf-95p7/GHSA-w7j2-35mf-95p7.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}