CVE-2018-25025: update patched version#2917
Conversation
After thoroughly inspecting the vulnerability, it is present until 0.7.19, inclusive and only patched in the first 1.0.0 version.
|
Please provide more context on what research led you to this conclusion. |
|
If you follow the links below, you can see the vulnerable code: The problem is undefined behavior because of mutable access to the original data while a mutable reference exists, see the unsafe section three lines below. Edit: Between the versions, there was commit |
After thoroughly inspecting the vulnerability, it is present until 0.7.19, inclusive and only patched in the first 1.0.0 version.
Affected crate(s)