VDB
Sign up
MEDIUM

GHSA-2rxc-gjrp-vjhx

Unsoundness in anstream

Details

When given a valid UTF8 string "ö\x1b😀", the function in crates/anstream/src/adapter/strip.rs will be confused. The UTF8 bytes are \xc3\xb6 then \x1b then \xf0\x9f\x98\x80.

When looping over "non-printable bytes" \x1b\xf0 will be considered as some non-printable sequence.

This will produce a broken str from the incorrectly segmented bytes via str::from_utf8_unchecked, and that should never happen.

Full credit goes to @Ralith who reviewed this code and asked @burakemir to follow up.

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/anstream
Introduced in: 0Fixed in: 0.6.8

Upgrade anstream to 0.6.8 or newer (ecosystem crates.io).

References