{"id":"GHSA-mcrf-7hf9-f6q5","summary":"Unchecked vector pre-allocation","details":"Affected versions of this crate pre-allocate memory on deserializing raw buffers without checking whether there is sufficient data available. This allows an attacker to do denial-of-service attacks by sending small msgpack messages that allocate gigabytes of memory.\n","aliases":["RUSTSEC-2017-0006"],"modified":"2023-11-08T04:21:02.280202Z","published":"2021-08-25T21:00:09Z","database_specific":{"github_reviewed_at":"2021-08-06T19:28:40Z","nvd_published_at":null,"cwe_ids":["CWE-400"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/3Hren/msgpack-rust/issues/151"},{"type":"PACKAGE","url":"https://github.com/3Hren/msgpack-rust"},{"type":"WEB","url":"https://rustsec.org/advisories/RUSTSEC-2017-0006.html"}],"affected":[{"package":{"name":"rmpv","ecosystem":"crates.io","purl":"pkg:cargo/rmpv"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.4.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/08/GHSA-mcrf-7hf9-f6q5/GHSA-mcrf-7hf9-f6q5.json"}}],"schema_version":"1.9.0"}