RUSTSEC-2021-0052

    Dashboard / Vulnerabilities / RUSTSEC-2021-0052

    RUSTSEC-2021-0052

    Published: 26 Feb 2021Last Modified: 15 Mar 2024

    Summary: Multiple functions can cause double-frees

    Details: The following functions in the crate are affected: ## `IdMap::clone_from` The `clone_from` implementation for `IdMap` drops the values present in the map and then begins cloning values from the other map. If a `.clone()` call pancics, then the afformentioned dropped elements can be freed again. ## `get_or_insert` `get_or_insert` reserves space for a value, before calling the user provided insertion function `f`. If the function `f` panics then uninitialized or previously freed memory can be dropped. ## `remove_set` When removing a set of elements, `ptr::drop_in_place` is called on each of the element to be removed. If the `Drop` impl of one of these elements panics then the previously dropped elements can be dropped again.

    Affected packages

    Package

    Name: id-map

    Purl: pkg:cargo/id-map

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0.0.0-0
    Fixed -None

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    RUSTSEC-2021-0052 | CVE-DB