An issue was discovered in the xcb crate through 2021-02-04 for Rust. It has a soundness violation because xcb::xproto::GetAtomNameReply::name() calls std::str::from_utf8_unchecked() on unvalidated bytes from an X server.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HXcb Project Xcb
APPXcb Project≤ 2021-02-04
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
Related vulnerabilities
CVE-2021-26956CRITICAL9.8PL ✓same product
Naruszenie poprawności typów (soundness violation) w bibliotece xcb dla Rust
CVE-2021-26957CRITICAL9.8PL ✓same product
Out-of-bounds read w Rust crate xcb — naruszenie soundness
CVE-2021-26958HIGH8.8same product
An issue was discovered in the xcb crate through 2021-02-04 for Rust. It has a soundness violation because tra...
CVE-2020-36205MEDIUM5.5same product
An issue was discovered in the xcb crate through 2020-12-10 for Rust. base::Error does not have soundness. Bec...