VDB
Sign up
—

RUSTSEC-2020-0034

Multiple security issues including data race, buffer overflow, and uninitialized memory drop

Details

`arr` crate contains multiple security issues. Specifically,

1. It incorrectly implements Sync/Send bounds, which allows to smuggle non-Sync/Send types across the thread boundary. 2. `Index` and `IndexMut` implementation does not check the array bound. 3. `Array::new_from_template()` drops uninitialized memory.

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/arr
Introduced in: 0.0.0-0

No fixed version published yet for arr. Pin to a known-safe version or switch to an alternative.

References