Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w65j-g6c7-g3m4

Опубликовано: 25 авг. 2021
Источник: github
Github: Прошло ревью

Описание

Multiple memory safety issues in actix-web

Affected versions contain multiple memory safety issues, such as:

  • Unsoundly coercing immutable references to mutable references
  • Unsoundly extending lifetimes of strings
  • Adding the Send marker trait to objects that cannot be safely sent between threads

This may result in a variety of memory corruption scenarios, most likely use-after-free.

A signficant refactoring effort has been conducted to resolve these issues.

Пакеты

Наименование

actix-web

rust
Затронутые версииВерсия исправления

< 0.7.15

0.7.15

Дефекты

CWE-362

Дефекты

CWE-362