RUSTSEC-2021-0051
Dashboard / Vulnerabilities / RUSTSEC-2021-0051
RUSTSEC-2021-0051
Summary: KeyValueReader passes uninitialized memory to Read instance
Details: The `KeyValueReader` type in affected versions of this crate set up an uninitialized memory buffer and passed them to be read in to a user-provided `Read` instance. The `Read` instance could read uninitialized memory and cause undefined behavior and miscompilations. This issue was fixed in commit [dd59b30](https://github.com/SolraBizna/outer_cgi/commit/dd59b3066e616a08e756f72de8dc3ab11b7036c4) by zero-initializing the buffers before passing them.
References: https://crates.io/crates/outer_cgi, https://rustsec.org/advisories/RUSTSEC-2021-0051.html, https://github.com/SolraBizna/outer_cgi/issues/1
Affected packages
Package
Name: outer_cgi
Purl: pkg:cargo/outer_cgi
Affected ranges
Type: SEMVER
Events:
