bug#47542: rust-stackvector package is vulnerable to CVE-2021-29939

2021-06-28 Thread zimoun
Hi, On Thu, 01 Apr 2021 at 15:47, Léo Le Bouter wrote: > CVE-2021-2993907:15 > An issue was discovered in the stackvector crate through 2021-02-19 for > Rust. There is an out-of-bounds write in StackVec::extend if size_hint > provides certain anomalous data. > > No fix released upstream y

bug#47542: rust-stackvector package is vulnerable to CVE-2021-29939

2021-04-01 Thread Léo Le Bouter via Bug reports for GNU Guix
CVE-2021-29939 07:15 An issue was discovered in the stackvector crate through 2021-02-19 for Rust. There is an out-of-bounds write in StackVec::extend if size_hint provides certain anomalous data. No fix released upstream yet: https://github.com/Alexhuszagh/rust-stackvector/issues/2 Out of boun