RUSTSEC-2021-0145
Dashboard / Vulnerabilities / RUSTSEC-2021-0145
Summary: Potential unaligned read
Details: On windows, `atty` dereferences a potentially unaligned pointer. In practice however, the pointer won't be unaligned unless a custom global allocator is used. In particular, the `System` allocator on windows uses `HeapAlloc`, which guarantees a large enough alignment. # atty is Unmaintained A Pull Request with a fix has been provided over a year ago but the maintainer seems to be unreachable. Last release of `atty` was almost 3 years ago. ## Possible Alternative(s) The below list has not been vetted in any way and may or may not contain alternatives; - [std::io::IsTerminal](https://doc.rust-lang.org/stable/std/io/trait.IsTerminal.html) - Stable since Rust 1.70.0 - [is-terminal](https://crates.io/crates/is-terminal) - Standalone crate supporting Rust older than 1.70.0
References: https://crates.io/crates/atty, https://rustsec.org/advisories/RUSTSEC-2021-0145.html, https://github.com/softprops/atty/issues/50, https://github.com/softprops/atty/pull/51, https://github.com/softprops/atty/issues/57
Affected packages
Package
Name: atty
Purl: pkg:cargo/atty
Affected ranges
Type: SEMVER
Events:
