« List of all CVEs

CVE-2021-29922

Published: 8/7/2021 Last updated: 8/3/2024 Reserved: 4/1/2021

library/std/src/net/parser.rs in Rust before 1.53.0 does not properly consider extraneous zero characters at the beginning of an IP address string, which (in some situations) allows attackers to bypass access control that is based on IP addresses, because of unexpected octal interpretation.

CNA assigner: mitre (8254265b-2729-46b6-b9e3-3dfca2d5bfca) Requested by: n/a

Opam packages affected (6)

conf-rust conf-rust-2018 conf-rust-2021 conf-rust-2024 conf-rust-llvm conf-rust-wasm

Products affected (1)

Product Vendor Version
n/a n/a 21.sp1 ap345755

References (12)