toodee is vulnerable to Heap-based Buffer Overflow
62
Medium Risk
Affected versions of this package contained an off-by-one error in the DrainCol::drop destructor, which caused an unsafe memory copy operation to exceed the bounds of its associated vector; an attacker could exploit this heap buffer overflow by crafting a scenario that triggers the removal of the first column from a TooDee object, potentially leading to a crash or arbitrary code execution when the vulnerable destructor runs.
You are affected if you are using a version that falls within the vulnerable range.
toodee is vulnerable to Heap-based Buffer Overflow in versions 0.2.0 - 0.5.0.
Upgrade the toodee library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant