GHSA-68p4-pjpf-xwcq
Dashboard / Vulnerabilities / GHSA-68p4-pjpf-xwcq
GHSA-68p4-pjpf-xwcq
Summary: insert_slice_clone can double drop if Clone panics.
Details: Affected versions of this crate used ptr::copy when inserting into the middle of a Vec. When ownership was temporarily duplicated during this copy, it calls the clone method of a user provided element. This issue can result in an element being double-freed if the clone call panics. Commit `20cb73d` fixed this issue by adding a set_len(0) call before operating on the vector to avoid dropping the elements during a panic.
References: https://nvd.nist.gov/vuln/detail/CVE-2021-26954, https://github.com/qwertz19281/rust_utils/issues/3, https://github.com/qwertz19281/rust_utils/commit/20cb73d, https://github.com/qwertz19281/rust_utils, https://rustsec.org/advisories/RUSTSEC-2021-0018.html
Affected packages
Package
Name: qwutils
Purl: pkg:cargo/qwutils
Affected ranges
Type: SEMVER
Events:
