VDB
Sign up
—

RUSTSEC-2021-0092

Deserialization functions pass uninitialized memory to user-provided Read

Details

Affected versions of this crate passed an uninitialized buffer to a user-provided `Read` instance in:

* `deserialize_binary` * `deserialize_string` * `deserialize_extension_others` * `deserialize_string_primitive`

This can result in safe `Read` implementations reading from the uninitialized buffer leading to undefined behavior.

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/messagepack-rs
Introduced in: 0.0.0-0

No fixed version published yet for messagepack-rs. Pin to a known-safe version or switch to an alternative.

References