RUSTSEC-2021-0018
Dashboard / Vulnerabilities / RUSTSEC-2021-0018
RUSTSEC-2021-0018
Summary: insert_slice_clone can double drop if Clone panics.
Details: Affected versions of this crate used `ptr::copy` when inserting into the middle of a `Vec`. When ownership was temporarily duplicated during this copy, it calls the clone method of a user provided element. This issue can result in an element being double-freed if the clone call panics. Commit `20cb73d` fixed this issue by adding a `set_len(0)` call before operating on the vector to avoid dropping the elements during a panic.
References: https://crates.io/crates/qwutils, https://rustsec.org/advisories/RUSTSEC-2021-0018.html, https://github.com/qwertz19281/rust_utils/issues/3
Affected packages
Package
Name: qwutils
Purl: pkg:cargo/qwutils
Affected ranges
Type: SEMVER
Events:
