Critical severityNVD Advisory· Published Dec 31, 2020· Updated Aug 5, 2024
CVE-2019-25002
CVE-2019-25002
Description
An issue was discovered in the sodiumoxide crate before 0.2.5 for Rust. generichash::Digest::eq compares itself to itself and thus has degenerate security properties.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
sodiumoxidecrates.io | >= 0.2.0, < 0.2.5 | 0.2.5 |
Affected products
2- rust/sodiumoxidedescription
Patches
Vulnerability mechanics
References
6- github.com/advisories/GHSA-wrvc-72w7-xpmjghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2019-25002ghsaADVISORY
- github.com/sodiumoxide/sodiumoxide/commit/38490723927f230498adf795153e6cd3cb08b6a8ghsaWEB
- github.com/sodiumoxide/sodiumoxide/pull/381ghsaWEB
- github.com/sodiumoxide/sodiumoxide/pull/381/commits/fae052b834b097ced9a89a8fff8466e18f383070ghsaWEB
- rustsec.org/advisories/RUSTSEC-2019-0026.htmlghsax_refsource_MISCWEB
News mentions
0No linked articles in our index yet.