{"id":"GHSA-mcrf-7hf9-f6q5","aliases":["RUSTSEC-2017-0006"],"url":"https://o3.security/vulnerability/GHSA-mcrf-7hf9-f6q5","summary":"Unchecked vector pre-allocation","details":"Affected versions of this crate pre-allocate memory on deserializing raw buffers without checking whether there is sufficient data available. This allows an attacker to do denial-of-service attacks by sending small msgpack messages that allocate gigabytes of memory.\n","published":"2021-08-25T21:00:09Z","modified":"2023-11-08T04:21:02.280202Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"crates.io","name":"rmpv","fixedVersion":"0.4.2"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/3Hren/msgpack-rust/issues/151"},{"type":"PACKAGE","url":"https://github.com/3Hren/msgpack-rust"},{"type":"WEB","url":"https://rustsec.org/advisories/RUSTSEC-2017-0006.html"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2023-11-08T04:21:02.280202Z"}}