{"id":"GHSA-mrrw-grhq-86gf","aliases":["RUSTSEC-2023-0015"],"url":"https://o3.security/vulnerability/GHSA-mrrw-grhq-86gf","summary":"Ascii (crate) allows out-of-bounds array indexing in safe code","details":"Affected version of this crate had implementation of `From<&mut AsciiStr>` for `&mut [u8]` and `&mut str`. This can result in out-of-bounds array indexing in safe code.\n\nThe flaw was corrected in commit [8a6c779](https://github.com/tomprogrammer/rust-ascii/pull/63/commits/8a6c7798c202766bd57d70fb8d12739dd68fb9dc) by removing those impls.","published":"2023-02-28T20:30:10Z","modified":"2026-07-16T19:00:21.951703667Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"crates.io","name":"ascii","fixedVersion":"0.9.3"}],"fix":{"url":"https://github.com/tomprogrammer/rust-ascii/pull/63/commits/8a6c7798c202766bd57d70fb8d12739dd68fb9dc","label":"tomprogrammer/rust-ascii#63"},"references":[{"type":"WEB","url":"https://github.com/tomprogrammer/rust-ascii/issues/64"},{"type":"WEB","url":"https://github.com/tomprogrammer/rust-ascii/pull/63/commits/8a6c7798c202766bd57d70fb8d12739dd68fb9dc"},{"type":"PACKAGE","url":"https://github.com/tomprogrammer/rust-ascii"},{"type":"WEB","url":"https://rustsec.org/advisories/RUSTSEC-2023-0015.html"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-16T19:00:21.951703667Z"}}