RUSTSEC-2021-0037
Dashboard / Vulnerabilities / RUSTSEC-2021-0037
RUSTSEC-2021-0037
Summary: Fix a use-after-free bug in diesels Sqlite backend
Details: We've misused `sqlite3_column_name`. The [SQLite](https://www.sqlite.org/c3ref/column_name.html) documentation states that the following: > The returned string pointer is valid until either the prepared statement > is destroyed by sqlite3_finalize() or until the statement is automatically > reprepared by the first call to sqlite3_step() for a particular > run or until the next call to sqlite3_column_name() > or sqlite3_column_name16() on the same column. As part of our `query_by_name` infrastructure we've first received all field names for the prepared statement and stored them as string slices for later use. After that we called `sqlite3_step()` for the first time, which invalids the pointer and therefore the stored string slice.
References: https://crates.io/crates/diesel, https://rustsec.org/advisories/RUSTSEC-2021-0037.html, https://github.com/diesel-rs/diesel/pull/2663
Affected packages
Package
Name: diesel
Purl: pkg:cargo/diesel
Affected ranges
Type: SEMVER
Events:
