RUSTSEC-2021-0004

Source
https://rustsec.org/advisories/RUSTSEC-2021-0004
Import Source
https://github.com/rustsec/advisory-db/blob/osv/crates/RUSTSEC-2021-0004.json
JSON Data
https://api.osv.dev/v1/vulns/RUSTSEC-2021-0004
Aliases
Published
2021-01-17T12:00:00Z
Modified
2023-11-08T04:05:16.553479Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L CVSS Calculator
Summary
Missing Send bound for Lazy
Details

All current versions of this crate allow causing data races in safe code.

The flaw will be fixed in the next release.

Database specific
{
    "license": "CC0-1.0"
}
References

Affected packages

crates.io / lazy-init

Package

Affected ranges

Type
SEMVER
Events
Introduced
0.0.0-0
Fixed
0.4.1-0

Ecosystem specific

{
    "affected_functions": null,
    "affects": {
        "os": [],
        "functions": [],
        "arch": []
    }
}

Database specific

{
    "cvss": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
    "informational": null,
    "categories": [
        "memory-corruption"
    ]
}