HIGH7.5
GHSA-4qr3-m7ww-hh9g
Use After Free in rusqlite
Details
An issue was discovered in the rusqlite crate 0.25.x before 0.25.4 and 0.26.x before 0.26.2 for Rust. commit_hook has a use-after-free.
Are you affected?
Enter the version of the package you're using.
Affected packages
crates.io/rusqlite
Introduced in:
0.25.0Fixed in: 0.25.4Upgrade rusqlite to 0.25.4 or newer (ecosystem crates.io).
crates.io/rusqlite
Introduced in:
0.26.0Fixed in: 0.26.2Upgrade rusqlite to 0.26.2 or newer (ecosystem crates.io).
References
- https://nvd.nist.gov/vuln/detail/CVE-2021-45717[ADVISORY]
- https://github.com/rusqlite/rusqlite/issues/1048[WEB]
- https://github.com/rusqlite/rusqlite[PACKAGE]
- https://raw.githubusercontent.com/rustsec/advisory-db/main/crates/rusqlite/RUSTSEC-2021-0128.md[WEB]
- https://rustsec.org/advisories/RUSTSEC-2021-0128.html[WEB]