VDB
Sign up
—

RUSTSEC-2021-0094

Window can read out of bounds if Read instance returns more bytes than buffer size

Details

`rdiff` performs a diff of two provided strings or files. As part of its reading code it uses the return value of a `Read` instance to set the length of its internal character vector.

If the `Read` implementation claims that it has read more bytes than the length of the provided buffer, the length of the vector will be set to longer than its capacity. This causes `rdiff` APIs to return uninitialized memory in its API methods.

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/rdiff
Introduced in: 0.0.0-0

No fixed version published yet for rdiff. Pin to a known-safe version or switch to an alternative.

References