- Reported
-
- Issued
-
- Package
-
mail-internals
(crates.io)
- Type
-
Vulnerability
- Categories
-
- Keywords
-
#mail
#mail-api
- Aliases
-
- References
-
- Patched
-
no patched versions
- Affected Functions
- Version
mail_internals::utils::vec_insert_bytes
-
Description
Incorrect reallocation logic in the function vec_insert_bytes causes a use-after-free.
This function does not have to be called directly to trigger the vulnerability because many methods on EncodingWriter call this function internally.
The mail-* suite is unmaintained and the upstream sources have been actively vandalised.
A fixed mail-internals-ng (and mail-headers-ng and mail-core-ng) crate has been published which fixes this, and a dependency on another unsound crate.
Advisory available under CC0-1.0
license.