CVE-2024-27284

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-27284
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-27284.json
Aliases
Published
2024-02-29T01:44:19Z
Modified
2024-03-02T20:26:47.041684Z
Details

cassandra-rs is a Cassandra (CQL) driver for Rust. Code that attempts to use an item (e.g., a row) returned by an iterator after the iterator has advanced to the next item will be accessing freed memory and experience undefined behaviour. The problem has been fixed in version 3.0.0.

References

Affected packages

Git / github.com/Metaswitch/cassandra-rs

Affected ranges

Type
GIT
Repo
https://github.com/Metaswitch/cassandra-rs
Events
Introduced
0The exact introduced commit is unknown
Fixed

Affected versions

0.*

0.10.0
0.10.1
0.10.2
0.11.0
0.12.0
0.13.0
0.13.1
0.13.2
0.14.0
0.14.1
0.15.0
0.15.1
0.16.0
0.17.0
0.17.1
0.17.2
0.6.0
0.6.1
0.6.10
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.8.0
0.8.1
0.8.2

1.*

1.0.0
1.1.0
1.2.0

2.*

2.0.0
2.0.1