Files
advisory-db/crates/generic-array/RUSTSEC-2020-0146.md
Sergey Potapov 1c7888e4ee Update RUSTSEC-2020-0146.md with list of patched versions (#789)
* Update RUSTSEC-2020-0146.md with list of patched versions

* Update crates/generic-array/RUSTSEC-2020-0146.md

Co-authored-by: Alex Gaynor <alex.gaynor@gmail.com>
2021-03-02 08:48:41 -05:00

624 B

[advisory]
id = "RUSTSEC-2020-0146"
package = "generic-array"
date = "2020-04-09"
url = "https://github.com/fizyk20/generic-array/issues/98"
categories = ["memory-corruption"]
keywords = ["soundness"]

[versions]
patched = [
    ">= 0.8.4, < 0.9.0",
    ">= 0.9.1, < 0.10.0",
    ">= 0.10.1, < 0.11.0",
    ">= 0.11.2, < 0.12.0",
    ">= 0.12.4, < 0.13.0",
    ">= 0.13.3",
]
unaffected = ["< 0.8.0"]

arr! macro erases lifetimes

Affected versions of this crate allowed unsoundly extending lifetimes using arr! macro. This may result in a variety of memory corruption scenarios, most likely use-after-free.