From e2d943375e82b6ec188d6fe2015a232bb0637544 Mon Sep 17 00:00:00 2001 From: JOE1994 Date: Sun, 24 Jan 2021 12:06:06 -0500 Subject: [PATCH] Report 0083-array-tools to RustSec --- crates/array-tools/RUSTSEC-0000-0000.md | 15 +++++++++++++++ 1 file changed, 15 insertions(+) create mode 100644 crates/array-tools/RUSTSEC-0000-0000.md diff --git a/crates/array-tools/RUSTSEC-0000-0000.md b/crates/array-tools/RUSTSEC-0000-0000.md new file mode 100644 index 0000000..71cd9ff --- /dev/null +++ b/crates/array-tools/RUSTSEC-0000-0000.md @@ -0,0 +1,15 @@ +```toml +[advisory] +id = "RUSTSEC-0000-0000" +package = "array-tools" +date = "2020-12-31" +url = "https://github.com/L117/array-tools/issues/2" +categories = ["memory-corruption"] + +[versions] +patched = [] +``` + +# `FixedCapacityDequeLike::clone()` can cause dropping uninitialized memory + +Affected versions of this crate don't guard against panics, so that partially uninitialized buffer is dropped when user-provided `T::clone()` panics in `FixedCapacityDequeLike::clone()`. This causes memory corruption.