VYPR
High severity7.5NVD Advisory· Published Nov 15, 2021· Updated Jun 17, 2026

CVE-2021-43620

CVE-2021-43620

Description

An issue was discovered in the fruity crate through 0.2.0 for Rust. Security-relevant validation of filename extensions is plausibly affected. Methods of NSString for conversion to a string may return a partial result. Because they call CStr::from_ptr on a pointer to the string buffer, the string is terminated at the first '\0' byte, which might not be the end of the string.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
fruitycrates.io
>= 0.1.0, < 0.3.00.3.0

Affected products

4
  • cpe:2.3:a:fruity_project:fruity:0.1.0:*:*:*:*:rust:*:*+ 1 more
    • cpe:2.3:a:fruity_project:fruity:0.1.0:*:*:*:*:rust:*:*
    • cpe:2.3:a:fruity_project:fruity:0.2.0:*:*:*:*:rust:*:*
  • fruity crate/fruity cratedescription
  • ghsa-coords
    Range: >= 0.1.0, < 0.3.0

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.