Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Vulnerable library protobuf version 1.2 #5

Open
beta-vulnerability-notify bot opened this issue Sep 19, 2019 · 0 comments
Open

Vulnerable library protobuf version 1.2 #5

beta-vulnerability-notify bot opened this issue Sep 19, 2019 · 0 comments

Comments

@beta-vulnerability-notify
Copy link

A vulnerability has been found in the library protobuf.

The description is:
Description Affected versions of this crate called Vec::reserve() on user-supplied input. This allows an attacker to cause an Out of Memory condition while calling the vulnerable method on untrusted data. More Info stepancheg/rust-protobuf#411 Patched Versions ^1.7.5 >= 2.6.0

Please fix this as soon as possible
Link to read more about the vulnerability:
https://watchers.firosolutions.com/vuln/view/RUSTSEC-2019-0003: protobuf: Out of Memory in stream::read_raw_bytes_into()

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

0 participants