Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-55m5-whcv-c49c

Опубликовано: 06 янв. 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Use of Uninitialized Resource in smallvec

Affected versions of this crate called mem::uninitialized() to create values of a user-supplied type T. This is unsound e.g. if T is a reference type (which must be non-null and thus may not remain uninitialized). The flaw was corrected by avoiding the use of mem::uninitialized(), using MaybeUninit instead.

Пакеты

Наименование

smallvec

rust
Затронутые версииВерсия исправления

< 0.6.13

0.6.13

EPSS

Процентиль: 46%
0.00231
Низкий

7.5 High

CVSS3

Дефекты

CWE-908

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 4 лет назад

An issue was discovered in the smallvec crate before 0.6.13 for Rust. It can create an uninitialized value of any type, including a reference type.

CVSS3: 7.5
nvd
около 4 лет назад

An issue was discovered in the smallvec crate before 0.6.13 for Rust. It can create an uninitialized value of any type, including a reference type.

CVSS3: 7.5
debian
около 4 лет назад

An issue was discovered in the smallvec crate before 0.6.13 for Rust. ...

EPSS

Процентиль: 46%
0.00231
Низкий

7.5 High

CVSS3

Дефекты

CWE-908