CRITICAL9.8
GHSA-rpcm-whqc-jfw8
Use after free in libflate
Details
An issue was discovered in the libflate crate before 0.1.25 for Rust. MultiDecoder::read has a use-after-free, leading to arbitrary code execution.
Are you affected?
Enter the version of the package you're using.
Affected packages
crates.io/libflate
Introduced in:
0.1.14Fixed in: 0.1.25Upgrade libflate to 0.1.25 or newer (ecosystem crates.io).
References
- https://nvd.nist.gov/vuln/detail/CVE-2019-15552[ADVISORY]
- https://github.com/sile/libflate/issues/35[WEB]
- https://github.com/sile/libflate/pull/37[WEB]
- https://github.com/sile/libflate/commit/ffeff7c65deac5a6f886db2a59bcae4e420e4706[WEB]
- https://github.com/sile/libflate[PACKAGE]
- https://rustsec.org/advisories/RUSTSEC-2019-0010.html[WEB]