CVE-2021-27377: Use After Free
Published Feb 18, 2021
·Updated
An issue was discovered in the yottadb crate before 1.2.0 for Rust. For some memory-allocation patterns, ydbsubscriptnextst and ydbsubscriptprevst have a use-after-free.
Affected Software
1 affected component
YottaDB Yottadb Rust<1.2.0
Event History
Feb 18, 2021
CVE Published
via MITRE·03:35 AM
Data Sourced
via MITRE·03:35 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2021-27377?
CVE-2021-27377 has a medium severity rating due to the potential for use-after-free vulnerabilities in memory allocation.
2
How do I fix CVE-2021-27377?
To fix CVE-2021-27377, upgrade the yottadb crate to version 1.2.0 or later.
3
What software is affected by CVE-2021-27377?
CVE-2021-27377 affects versions of yottadb crate before 1.2.0 used in Rust applications.
4
What are the consequences of CVE-2021-27377?
The consequences of CVE-2021-27377 include the risk of application crashes and potential exploitation through use-after-free vulnerabilities.
5
Is there a workaround for CVE-2021-27377?
There are no known workarounds for CVE-2021-27377; updating the crate is the recommended solution.