The From implementation for Vec was not properly implemented, returning a vector backed by freed memory. This could lead to memory corruption or be exploited to cause undefined behavior.
A fix was published in version 0.1.3.
References:An open API service providing security vulnerability metadata for many open source software ecosystems.
Affected Packages | Affected Versions | Fixed Versions | |
---|---|---|---|
cargo:chttp | >= 0.1.1, < 0.1.3 | 0.1.3 | |
Affected Version RangesAll affected versions0.1.1, 0.1.2 All unaffected versions0.1.3, 0.1.4, 0.1.5, 0.2.0, 0.2.1, 0.2.2, 0.2.3, 0.2.4, 0.3.0, 0.3.1, 0.4.0, 0.4.1, 0.4.2, 0.4.3, 0.4.4, 0.4.5, 0.5.0, 0.5.1, 0.5.2, 0.5.3, 0.5.4, 0.5.5 |
The From implementation for Vec was not properly implemented, returning a vector backed by freed memory. This could lead to memory corruption or be exploited to cause undefined behavior.
A fix was published in version 0.1.3.
References: