CVE-2020-35865 is a high-severity vulnerability (CVSS 7.5) affecting the os_str_bytes crate for Rust, specifically versions prior to 2.0.0. The issue stems from incorrect assumptions regarding the behavior of char::from_u32_unchecked, which could lead to a denial of service. The vulnerability is network-exploitable with low attack complexity and no user interaction required, but it currently lacks public exploit code, active exploitation, or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.0.0CPE matchmatch criteria | cpe:2.3:a:os_str_bytes_project:os_str_bytes:*:*:*:*:*:rust:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.