GHSA-qpjr-ch72-2qq4
Dashboard / Vulnerabilities / GHSA-qpjr-ch72-2qq4
GHSA-qpjr-ch72-2qq4
Summary: Use after free in portaudio-rs
Details: Affected versions of this crate is not panic safe within callback functions stream_callback and stream_finished_callback. The call to user-provided closure might panic before a mem::forget call, which then causes a use after free that grants attacker to control the callback function pointer. This allows an attacker to construct an arbitrary code execution .
References: https://nvd.nist.gov/vuln/detail/CVE-2019-16881, https://github.com/mvdnes/portaudio-rs/issues/20, https://github.com/mvdnes/portaudio-rs/commit/7466df019f6739732fd91401017942c22364ef61, https://github.com/mvdnes/portaudio-rs, https://rustsec.org/advisories/RUSTSEC-2019-0022.html
Affected packages
Package
Name: portaudio-rs
Purl: pkg:cargo/portaudio-rs
Affected ranges
Type: SEMVER
Events:
