CRITICAL9.8
GHSA-28ph-f7gx-fqj8
Data races in rusqlite
Details
An issue was discovered in the rusqlite crate before 0.23.0 for Rust. Memory safety can be violated via create_module.
Are you affected?
Enter the version of the package you're using.
Affected packages
crates.io/rusqlite
Introduced in:
0Fixed in: 0.23.0Upgrade rusqlite to 0.23.0 or newer (ecosystem crates.io).
References
- https://nvd.nist.gov/vuln/detail/CVE-2020-35867[ADVISORY]
- https://github.com/rusqlite/rusqlite/commit/3c6b57fe1b2cc87e7ebecde43dd836ffb1c4ea5c[WEB]
- https://github.com/rusqlite/rusqlite[PACKAGE]
- https://github.com/rusqlite/rusqlite/releases/tag/0.23.0[WEB]
- https://rustsec.org/advisories/RUSTSEC-2020-0014.html[WEB]