—
RUSTSEC-2021-0092
Deserialization functions pass uninitialized memory to user-provided Read
Details
Affected versions of this crate passed an uninitialized buffer to a user-provided `Read` instance in:
* `deserialize_binary` * `deserialize_string` * `deserialize_extension_others` * `deserialize_string_primitive`
This can result in safe `Read` implementations reading from the uninitialized buffer leading to undefined behavior.
Are you affected?
Enter the version of the package you're using.
Affected packages
crates.io/messagepack-rs
Introduced in:
0.0.0-0No fixed version published yet for messagepack-rs. Pin to a known-safe version or switch to an alternative.