An issue was discovered in the smallvec crate before 0.6.13 for Rust. It can create an uninitialized value of any type, including a reference type.
The product uses or accesses a resource that has not been initialized.
Link | Tags |
---|---|
https://rustsec.org/advisories/RUSTSEC-2018-0018.html | issue tracking exploit third party advisory |
https://raw.githubusercontent.com/rustsec/advisory-db/main/crates/smallvec/RUSTSEC-2018-0018.md | third party advisory |
https://github.com/servo/rust-smallvec/commit/e64afc8c473d43e375ab42bd33db2d0d4ac4e41b |