CVE-2019-25055

HIGH7.5EPSS 0.33%

Fix for UB in failure to catch panics crossing FFI boundaries

Published: 8/25/2021Modified: 11/8/2023
Also known as:GHSA-wcxc-jf6c-8rx9GHSA-xvcg-2q82-r87jRUSTSEC-2019-0038

Description

Affected versions of this crate failed to catch panics crossing FFI boundaries via callbacks, which is a form of UB. This flaw was corrected by [this commit][1] which was included in version 2.6.0. [1]: https://github.com/jnqnfe/pulse-binding-rust/commit/7fd282aef7787577c385aed88cb25d004b85f494

Affected packages (3)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1HIGH7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

References (6)