PT-2024-40524 · Unknown · Fast-Float

Published

2024-11-12

·

Updated

2024-11-12

CVSS v4.0

2.7

Low

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U
Name of the Vulnerable Software and Affected Versions: fast-float (affected versions not specified)
Description: The fast-float library contains soundness issues, including undefined behavior when checking input length and functions marked as safe with non-local safety guarantees. The library is also unmaintained. For parsing floating-point numbers, third-party crates are no longer needed due to a fast float parsing algorithm being merged into libcore.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Related Identifiers

GHSA-X8JH-XJ3X-GX3C

Affected Products

Fast-Float