VDB
Sign up
—

RUSTSEC-2020-0159

Potential segfault in `localtime_r` invocations

Details

### Impact

Unix-like operating systems may segfault due to dereferencing a dangling pointer in specific circumstances. This requires an environment variable to be set in a different thread than the affected functions. This may occur without the user's knowledge, notably in a third-party library.

### Workarounds

No workarounds are known.

### References

- [time-rs/time#293](https://github.com/time-rs/time/issues/293)

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/chrono
Introduced in: 0.0.0-0Fixed in: 0.4.20

Upgrade chrono to 0.4.20 or newer (ecosystem crates.io).

References