RUSTSEC-2019-0010
Dashboard / Vulnerabilities / RUSTSEC-2019-0010
RUSTSEC-2019-0010
Summary: MultiDecoder::read() drops uninitialized memory of arbitrary type on panic in client code
Details: Affected versions of libflate have set a field of an internal structure with a generic type to an uninitialized value in `MultiDecoder::read()` and reverted it to the original value after the function completed. However, execution of `MultiDecoder::read()` could be interrupted by a panic in caller-supplied `Read` implementation. This would cause `drop()` to be called on uninitialized memory of a generic type implementing `Read`. This is equivalent to a use-after-free vulnerability and could allow an attacker to gain arbitrary code execution. The flaw was corrected by aborting immediately instead of unwinding the stack in case of panic within `MultiDecoder::read()`. The issue was discovered and fixed by Shnatsel.
References: https://crates.io/crates/libflate, https://rustsec.org/advisories/RUSTSEC-2019-0010.html, https://github.com/sile/libflate/issues/35
Affected packages
Package
Name: libflate
Purl: pkg:cargo/libflate
Affected ranges
Type: SEMVER
Events:
