—
RUSTSEC-2021-0053
'merge_sort::merge()' crashes with double-free for `T: Drop`
Details
In the affected versions of this crate, `merge_sort::merge()` wildly duplicates and drops ownership of `T` without guarding against double-free. Due to such implementation, simply invoking `merge_sort::merge()` on `Vec<T: Drop>` can cause **double free** bugs.
Are you affected?
Enter the version of the package you're using.
Affected packages
crates.io/algorithmica
Introduced in:
0.0.0-0No fixed version published yet for algorithmica. Pin to a known-safe version or switch to an alternative.