xmas-elf is vulnerable to Out-of-bounds Read
35
Low Risk
Affected versions of this crate improperly validate the index argument of HashTable::get_bucket and HashTable::get_chain, checking it only against the input-controlled bucket_count and chain_count fields but not against the actual size of the ELF section. Consequently, a malformed ELF file can trigger out-of-bounds reads in applications using the HashTable API by setting these fields to excessively large values that extend beyond the hash table section and introducing corresponding out-of-bounds indexes elsewhere in the ELF file.
You are affected if you are using a version which is within vulnerability ranges and using template::UriTemplateStr.
xmas-elf is vulnerable to Out-of-bounds Read in versions 0.1 - 0.9.1.
Upgrade the xmas-elf library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant