High severity7.5NVD Advisory· Published Nov 15, 2021· Updated Jun 17, 2026
CVE-2021-43620
CVE-2021-43620
Description
An issue was discovered in the fruity crate through 0.2.0 for Rust. Security-relevant validation of filename extensions is plausibly affected. Methods of NSString for conversion to a string may return a partial result. Because they call CStr::from_ptr on a pointer to the string buffer, the string is terminated at the first '\0' byte, which might not be the end of the string.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
fruitycrates.io | >= 0.1.0, < 0.3.0 | 0.3.0 |
Affected products
4cpe:2.3:a:fruity_project:fruity:0.1.0:*:*:*:*:rust:*:*+ 1 more
- cpe:2.3:a:fruity_project:fruity:0.1.0:*:*:*:*:rust:*:*
- cpe:2.3:a:fruity_project:fruity:0.2.0:*:*:*:*:rust:*:*
- fruity crate/fruity cratedescription
Patches
Vulnerability mechanics
References
5- github.com/nvzqz/fruity/issues/14nvdExploitIssue TrackingPatchThird Party AdvisoryWEB
- github.com/rustsec/advisory-db/pull/1102nvdExploitPatchThird Party AdvisoryWEB
- rustsec.org/advisories/RUSTSEC-2021-0123.htmlnvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-h352-g5vw-3926ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2021-43620ghsaADVISORY
News mentions
0No linked articles in our index yet.