An issue was discovered in the messagepack-rs crate through 2021-01-26 for Rust. deserialize_binary may read from uninitialized memory locations.
The product uses or accesses a resource that has not been initialized.
Link | Tags |
---|---|
https://rustsec.org/advisories/RUSTSEC-2021-0092.html | third party advisory |
https://raw.githubusercontent.com/rustsec/advisory-db/main/crates/messagepack-rs/RUSTSEC-2021-0092.md | third party advisory |