{"id":"CVE-2021-45705","aliases":["GHSA-r57r-j98g-587f","RUSTSEC-2021-0114"],"url":"https://o3.security/vulnerability/CVE-2021-45705","summary":"Aliased mutable references from `tls_rand` & `TlsWyRand`","details":"`TlsWyRand`'s implementation of `Deref` unconditionally dereferences a raw pointer, and returns \nmultiple mutable references to the same object, which is undefined behavior.\n","published":"2022-06-17T00:13:24Z","modified":"2023-11-08T04:07:22.929289Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"crates.io","name":"nanorand","fixedVersion":"0.6.1"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/Absolucy/nanorand-rs/issues/28"},{"type":"PACKAGE","url":"https://github.com/Absolucy/nanorand-rs"},{"type":"WEB","url":"https://rustsec.org/advisories/RUSTSEC-2021-0114.html"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2023-11-08T04:07:22.929289Z"}}