Описание
Use After Free in tremor-script
An issue was discovered in the tremor-script crate before 0.11.6 for Rust. A merge operation may result in a use-after-free.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2021-45702
- https://github.com/tremor-rs/tremor-runtime/pull/1217
- https://github.com/tremor-rs/tremor-runtime/commit/1a2efcdbe68e5e7fd0a05836ac32d2cde78a0b2e
- https://raw.githubusercontent.com/rustsec/advisory-db/main/crates/tremor-script/RUSTSEC-2021-0111.md
- https://rustsec.org/advisories/RUSTSEC-2021-0111.html
Пакеты
Наименование
tremor-script
rust
Затронутые версииВерсия исправления
>= 0.7.2, < 0.11.6
0.11.6
Связанные уязвимости
CVSS3: 7.5
nvd
около 4 лет назад
An issue was discovered in the tremor-script crate before 0.11.6 for Rust. A merge operation may result in a use-after-free.