{"id":"GHSA-f9g6-fp84-fv92","summary":"impl `FromMdbValue` for bool is unsound","details":"The implementation of `FromMdbValue` has several unsoundness issues. First of all, it allows to reinterpret arbitrary bytes as a bool and could make undefined behavior happen with safe function. Secondly, it allows transmuting pointer without taking memory layout into consideration. The details of reproducing the bug are available [here](https://github.com/vhbit/lmdb-rs/issues/67).\n","aliases":["RUSTSEC-2023-0047"],"modified":"2023-11-08T04:18:55.242781Z","published":"2023-07-19T22:09:38Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2023-07-19T22:09:38Z","nvd_published_at":null,"cwe_ids":[],"severity":"MODERATE"},"references":[{"type":"WEB","url":"https://github.com/vhbit/lmdb-rs/issues/67"},{"type":"PACKAGE","url":"https://github.com/vhbit/lmdb-rs"},{"type":"WEB","url":"https://rustsec.org/advisories/RUSTSEC-2023-0047.html"}],"affected":[{"package":{"name":"lmdb-rs","ecosystem":"crates.io","purl":"pkg:cargo/lmdb-rs"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"last_affected":"0.7.6"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/07/GHSA-f9g6-fp84-fv92/GHSA-f9g6-fp84-fv92.json"}}],"schema_version":"1.9.0"}