CRITICAL9.8
GHSA-6wp2-fw3v-mfmc
Memory corruption in array-tools
Details
An issue was discovered in the array-tools crate before 0.3.2 for Rust. Affected versions of this crate don't guard against panics, so that partially uninitialized buffer is dropped when user-provided `T::clone()` panics in `FixedCapacityDequeLike<T, A>::clone()`. This causes memory corruption.
Are you affected?
Enter the version of the package you're using.
Affected packages
crates.io/array-tools
Introduced in:
0Fixed in: 0.3.2Upgrade array-tools to 0.3.2 or newer (ecosystem crates.io).
References
- https://nvd.nist.gov/vuln/detail/CVE-2020-36452[ADVISORY]
- https://github.com/L117/array-tools/issues/2[WEB]
- https://github.com/L117/array-tools[PACKAGE]
- https://raw.githubusercontent.com/rustsec/advisory-db/main/crates/array-tools/RUSTSEC-2020-0132.md[WEB]
- https://rustsec.org/advisories/RUSTSEC-2020-0132.html[WEB]