The Rust Programming Language Standard Library 1.34.x before 1.34.2 contains a stabilized method which, if overridden, can violate Rust's safety guarantees and cause memory unsafety. If the Error::type_id method is overridden then any type can be safely cast to any other type, causing memory safety vulnerabilities in safe code (e.g., out-of-bounds write or read). Code that does not manually implement Error::type_id is unaffected.
{
"unresolved_ranges": [
{
"extracted_events": [
{
"last_affected": "29"
},
{
"last_affected": "30"
}
],
"cpes": [
"cpe:2.3:o:fedoraproject:fedora:29:*:*:*:*:*:*:*",
"cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*"
],
"vendor_product": "fedoraproject:fedora",
"source": "CPE_FIELD"
},
{
"extracted_events": [
{
"last_affected": "15.1"
}
],
"cpes": [
"cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:*"
],
"vendor_product": "opensuse:leap",
"source": "CPE_FIELD"
}
]
}