Skip to content

RUSTSEC-2024-0437: Crash due to uncontrolled recursion in protobuf crate #743

Open
@github-actions

Description

@github-actions

Crash due to uncontrolled recursion in protobuf crate

Details
Package protobuf
Version 2.28.0
URL stepancheg/rust-protobuf#749
Date 2024-12-12

Affected version of this crate did not properly parse unknown fields when parsing a user-supplied input.

This allows an attacker to cause a stack overflow when parsing the mssage on untrusted data.

See advisory page for additional details.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    • Status

      Triage needed

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions