CRITICAL9.8
GHSA-2v78-j59h-fmpf
Heap overflow or corruption in safe-transmute
Details
Affected versions of this crate switched the length and capacity arguments in the Vec::from_raw_parts() constructor, which could lead to memory corruption or data leakage.
Are you affected?
Enter the version of the package you're using.
Affected packages
crates.io/safe-transmute
Introduced in:
0.4.0Fixed in: 0.10.1Upgrade safe-transmute to 0.10.1 or newer (ecosystem crates.io).
References
- https://nvd.nist.gov/vuln/detail/CVE-2018-21000[ADVISORY]
- https://github.com/nabijaczleweli/safe-transmute-rs/pull/36[WEB]
- https://github.com/nabijaczleweli/safe-transmute-rs/commit/a134e06d740f9d7c287f74c0af2cd06206774364[WEB]
- https://github.com/nabijaczleweli/safe-transmute-rs[PACKAGE]
- https://rustsec.org/advisories/RUSTSEC-2018-0013.html[WEB]