An issue was discovered in the failure crate through 0.1.5 for Rust. It may introduce "compatibility hazards" in some applications, and has a type confusion flaw when downcasting. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: This may overlap CVE-2019-25010
{
"binaries": [
{
"binary_name": "librust-failure+backtrace-dev",
"binary_version": "0.1.5-1build1"
},
{
"binary_name": "librust-failure+default-dev",
"binary_version": "0.1.5-1build1"
},
{
"binary_name": "librust-failure+derive-dev",
"binary_version": "0.1.5-1build1"
},
{
"binary_name": "librust-failure+failure-derive-dev",
"binary_version": "0.1.5-1build1"
},
{
"binary_name": "librust-failure+std-dev",
"binary_version": "0.1.5-1build1"
},
{
"binary_name": "librust-failure-dev",
"binary_version": "0.1.5-1build1"
}
]
}
{
"binaries": [
{
"binary_name": "librust-failure+backtrace-dev",
"binary_version": "0.1.7-1"
},
{
"binary_name": "librust-failure+default-dev",
"binary_version": "0.1.7-1"
},
{
"binary_name": "librust-failure+derive-dev",
"binary_version": "0.1.7-1"
},
{
"binary_name": "librust-failure-dev",
"binary_version": "0.1.7-1"
}
]
}
{
"binaries": [
{
"binary_name": "librust-failure+backtrace-dev",
"binary_version": "0.1.7-1"
},
{
"binary_name": "librust-failure+default-dev",
"binary_version": "0.1.7-1"
},
{
"binary_name": "librust-failure+derive-dev",
"binary_version": "0.1.7-1"
},
{
"binary_name": "librust-failure-dev",
"binary_version": "0.1.7-1"
}
]
}