GHSA-5873-6fwq-463f
stellar-strkey vulnerable to panic in SignedPayload::from_payload
Details
### Impact Panic vulnerability when a specially crafted payload is used. This is because of the following calculation: ```rust inner_payload_len + (4 - inner_payload_len % 4) % 4 ``` If `inner_payload_len` is `0xffffffff`, `(4 - inner_payload_len % 4) % 4 = 1` so ```rust inner_payload_len + (4 - inner_payload_len % 4) % 4 = u32::MAX + 1 ``` which overflow.
### Patches Check that `inner_payload_len` is not above 64 which should never be the case. Patched in version 0.0.8
### Workarounds Sanitize input payload before it is passed to the vulnerable function so that bytes in `payload[32..32+4]` and parsed as a `u32` is not above 64.
### References GitHub issue #58
Are you affected?
Enter the version of the package you're using.
Affected packages
0Fixed in: 0.0.8Upgrade stellar-strkey to 0.0.8 or newer (ecosystem crates.io).
References
- https://github.com/stellar/rs-stellar-strkey/security/advisories/GHSA-5873-6fwq-463f[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2023-46135[ADVISORY]
- https://github.com/stellar/rs-stellar-strkey/issues/58[WEB]
- https://github.com/stellar/rs-stellar-strkey/pull/59[WEB]
- https://github.com/stellar/rs-stellar-strkey/commit/83adad0f5b1cda693c7ba8524d395add8077865f[WEB]
- https://github.com/stellar/rs-stellar-strkey[PACKAGE]
- https://github.com/stellar/rs-stellar-strkey/releases/tag/v0.0.8[WEB]