{"id":"GHSA-rcx8-48pc-v9q8","aliases":["RUSTSEC-2023-0054"],"url":"https://o3.security/vulnerability/GHSA-rcx8-48pc-v9q8","summary":"mail-internals use-after-free vulnerability in `vec_insert_bytes`","details":"Incorrect reallocation logic in the function [`vec_insert_bytes`](https://docs.rs/mail-internals/0.2.3/mail_internals/utils/fn.vec_insert_bytes.html) causes a use-after-free.\n\nThis function does not have to be called directly to trigger the vulnerability because many methods on [`EncodingWriter`](https://docs.rs/mail-internals/0.2.3/mail_internals/encoder/struct.EncodingWriter.html) call this function internally.\n\nThe mail-\\* suite is unmaintained and the upstream sources have been actively vandalised.\nA fixed `mail-internals-ng` (and `mail-headers-ng` and `mail-core-ng`) crate has been published which fixes this, and a dependency on another unsound crate.\n","published":"2023-08-24T22:20:47Z","modified":"2023-11-08T04:22:42.487180Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"crates.io","name":"mail-internals","fixedVersion":null}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/rustsec/advisory-db/blob/main/crates/mail-internals/RUSTSEC-2023-0054.md"},{"type":"WEB","url":"https://rustsec.org/advisories/RUSTSEC-2023-0054.html"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2023-11-08T04:22:42.487180Z"}}