toodee is vulnerable to Heap-based Buffer Overflow
62
Medium Risk
Affected versions of this package contained an off-by-one error in the DrainCol::drop destructor, which caused an unsafe memory copy operation to exceed the bounds of its associated vector; an attacker could exploit this heap buffer overflow by crafting a scenario that triggers the removal of the first column from a TooDee object, potentially leading to a crash or arbitrary code execution when the vulnerable destructor runs.
You are affected if you are using a version that falls within the vulnerable range.
toodee is vulnerable to Heap-based Buffer Overflow in versions 0.2.0 - 0.5.0.
Upgrade the toodee library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant