CVE-2019-1010299 is an information exposure vulnerability affecting Rust Programming Language Standard Library versions 1.18.0 and later, specifically within the Debug trait implementation for std::collections::vec_deque::Iter. When debug printing an iterator over an empty VecDeque, the contents of uninitialized memory could be exposed to strings or log files. Rated Medium severity (CVSS 5.3), this vulnerability has a network attack vector and low attack complexity, potentially leading to information disclosure (CWE-200, CWE-908). There is no impact on integrity or availability. Currently, there is no evidence of active exploitation, nor are there any known public exploits (Metasploit, Nuclei, ExploitDB). Community discussion and media coverage for this CVE are minimal, indicating low public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.18.0, < 1.30.0CPE matchmatch criteria | cpe:2.3:a:rust-lang:rust:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.