RUSTSEC-2021-0038

    Dashboard / Vulnerabilities / RUSTSEC-2021-0038

    RUSTSEC-2021-0038

    Published: 6 Mar 2021Last Modified: 15 Mar 2024

    Summary: Multiple memory safety issues

    Details: Affected versions contain multiple memory safety issues, such as: - Setting a multi label type where an image doesn't exist would lead to a NULL pointer dereference. - Setting a window icon using a non-raster image (which FLTK rasterizes lazily) would lead to a NULL dereference. - Pixmap constructor would not check for correct pixmaps which could lead to out-of bound reads.

    Affected packages

    Package

    Name: fltk

    Purl: pkg:cargo/fltk

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0.0.0-0
    Fixed -0.15.3

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    RUSTSEC-2021-0038 | CVE-DB