CRITICAL9.8
GHSA-hr52-f9vp-582c
Use of Uninitialized Resource in messagepack-rs.
Details
An issue was discovered in the messagepack-rs crate through 2021-01-26 for Rust. deserialize_extension_others may read from uninitialized memory locations.
Are you affected?
Enter the version of the package you're using.
Affected packages
crates.io/messagepack-rs
Introduced in:
0No fixed version published yet for messagepack-rs. Pin to a known-safe version or switch to an alternative.
References
- https://nvd.nist.gov/vuln/detail/CVE-2021-45692[ADVISORY]
- https://github.com/otake84/messagepack-rs/issues/2[WEB]
- https://github.com/otake84/messagepack-rs[PACKAGE]
- https://raw.githubusercontent.com/rustsec/advisory-db/main/crates/messagepack-rs/RUSTSEC-2021-0092.md[WEB]
- https://rustsec.org/advisories/RUSTSEC-2021-0092.html[WEB]