CVE-2021-26305
29.01.2021, 03:15
An issue was discovered in Deserializer::read_vec in the cdr crate before 0.2.4 for Rust. A user-provided Read implementation can gain access to the old contents of newly allocated heap memory, violating soundness.Enginsight
Vendor | Product | Version |
---|---|---|
cdr_project | cdr | 𝑥 < 0.2.4 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration