GHSA-r45x-ghr2-qjxc
Dashboard / Vulnerabilities / GHSA-r45x-ghr2-qjxc
GHSA-r45x-ghr2-qjxc
Summary: Duplicate Advisory: `#[zeroize(drop)]` doesn't implement `Drop` for `enum`s
Details: ## Duplicate Advisory This advisory is a duplicate of [GHSA-c5hx-w945-j4pq](https://github.com/advisories/GHSA-c5hx-w945-j4pq). This link is preserved to maintain external references. ## Original Description Affected versions of this crate did not implement `Drop` when `#[zeroize(drop)]` was used on an `enum`. This can result in memory not being zeroed out after dropping it, which is exactly what is intended when adding this attribute. The flaw was corrected in version 1.2 and `#[zeroize(drop)]` on `enum`s now properly implements `Drop`.
References: https://github.com/iqlusioninc/crates/issues/876, https://github.com/iqlusioninc/crates, https://rustsec.org/advisories/RUSTSEC-2021-0115.html
Affected packages
Package
Name: zeroize_derive
Purl: pkg:cargo/zeroize_derive
Affected ranges
Type: SEMVER
Events:
