This advisory is a duplicate of GHSA-c5hx-w945-j4pq. This link is preserved to maintain external references.
Affected versions of this crate did not implement Drop
when #[zeroize(drop)]
was used on an enum
.
This can result in memory not being zeroed out after dropping it, which is exactly what is intended when adding this attribute.
The flaw was corrected in version 1.2 and #[zeroize(drop)]
on enum
s now properly implements Drop
.
{ "nvd_published_at": null, "cwe_ids": [ "CWE-226" ], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2022-06-17T00:30:52Z" }