Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f95p-4cv5-8w8x

Опубликовано: 04 дек. 2024
Источник: github
Github: Прошло ревью

Описание

linkme fails to ensure slice elements match the slice's declared type

Affected versions allow populating a DistributedSlice of T with elements of an arbitrary other type that coerces to T. For example, elements of type &&str could end up in a slice of type [&str], since &&str coerces to &str via a deref coercion.

The flaw was corrected by implementing typechecking for distributed slice elements in such a way that coercion no longer occurs. The element's type must be a subtype of the slice's declared element type.

Пакеты

Наименование

linkme

rust
Затронутые версииВерсия исправления

< 0.3.24

0.3.24