-
Notifications
You must be signed in to change notification settings - Fork 374
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Merge pull request #222 from dbrgn/prost-stackoverflow
Add advisory for prost stack overflow
- Loading branch information
Showing
1 changed file
with
20 additions
and
0 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,20 @@ | ||
[advisory] | ||
id = "RUSTSEC-0000-0000" | ||
package = "prost" | ||
date = "2020-01-16" | ||
title = "Parsing a specially crafted message can result in a stack overflow" | ||
description = """ | ||
Affected versions of this crate contained a bug in which decoding untrusted | ||
input could overflow the stack. | ||
On architectures with stack probes (like x86), this can be used for denial of | ||
service attacks, while on architectures without stack probes (like ARM) | ||
overflowing the stack is unsound and can result in potential memory corruption | ||
(or even RCE). | ||
The flaw was quickly corrected by @danburkert and released in version 0.6.1. | ||
""" | ||
patched_versions = [">= 0.6.1"] | ||
url = "https://github.com/danburkert/prost/issues/267" | ||
categories = ["denial-of-service", "memory-corruption"] | ||
keywords = ["stack overflow"] |