{"id":"RUSTSEC-2021-0038","summary":"Multiple memory safety issues","details":"Affected versions contain multiple memory safety issues, such as:\n\n - Setting a multi label type where an image doesn't exist would lead to a NULL pointer dereference.\n - Setting a window icon using a non-raster image (which FLTK rasterizes lazily) would lead to a NULL dereference.\n - Pixmap constructor would not check for correct pixmaps which could lead to out-of bound reads.","aliases":["CVE-2021-28306","CVE-2021-28307","CVE-2021-28308","GHSA-5pg8-h4gv-m3p8","GHSA-7qcc-g2m9-8533","GHSA-vjmg-pc8h-p6p8"],"modified":"2024-03-15T00:05:17.414684Z","published":"2021-03-06T12:00:00Z","database_specific":{"license":"CC0-1.0"},"references":[{"type":"PACKAGE","url":"https://crates.io/crates/fltk"},{"type":"ADVISORY","url":"https://rustsec.org/advisories/RUSTSEC-2021-0038.html"},{"type":"REPORT","url":"https://github.com/MoAlyousef/fltk-rs/issues/519"}],"affected":[{"package":{"name":"fltk","ecosystem":"crates.io","purl":"pkg:cargo/fltk"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0.0.0-0"},{"fixed":"0.15.3"}]}],"ecosystem_specific":{"affected_functions":null,"affects":{"functions":["fltk::image::Pixmap::new","fltk::prelude::WidgetExt::set_label_type","fltk::prelude::WindowExt::set_icon"],"os":[],"arch":[]}},"database_specific":{"categories":[],"cvss":null,"informational":null,"source":"https://github.com/rustsec/advisory-db/blob/osv/crates/RUSTSEC-2021-0038.json"}}],"schema_version":"1.7.3"}