High severityNVD Advisory· Published Mar 5, 2021· Updated Aug 3, 2024
CVE-2021-28030
CVE-2021-28030
Description
An issue was discovered in the truetype crate before 0.30.1 for Rust. Attackers can read the contents of uninitialized memory locations via a user-provided Read operation within Tape::take_bytes.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
truetypecrates.io | < 0.30.1 | 0.30.1 |
Affected products
2- Rust/truetypedescription
Patches
Vulnerability mechanics
References
4- github.com/advisories/GHSA-v7q4-97x4-4qw2ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2021-28030ghsaADVISORY
- github.com/bodoni/truetype/issues/11ghsaWEB
- rustsec.org/advisories/RUSTSEC-2021-0029.htmlghsax_refsource_MISCWEB
News mentions
0No linked articles in our index yet.