Vulnerability Details CVE-2021-26305
An issue was discovered in Deserializer::read_vec in the cdr crate before 0.2.4 for Rust. A user-provided Read implementation can gain access to the old contents of newly allocated heap memory, violating soundness.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.005
EPSS Ranking 65.2%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 7.5
Products affected by CVE-2021-26305
-
cpe:2.3:a:cdr_project:cdr:-
-
cpe:2.3:a:cdr_project:cdr:0.2.0
-
cpe:2.3:a:cdr_project:cdr:0.2.1
-
cpe:2.3:a:cdr_project:cdr:0.2.2
-
cpe:2.3:a:cdr_project:cdr:0.2.3