VDB
Sign up
—

RUSTSEC-2022-0031

Panic due to improper UTF-8 indexing

Details

When parsing untrusted rulex expressions, rulex may panic, possibly enabling a Denial of Service attack. This happens when the expression contains a multi- byte UTF-8 code point in a string literal or after a backslash, because rulex tries to slice into the code point and panics as a result.

The flaw was corrected in commits `fac6d58b25` and `330b3534e7` by using `len_utf8()` to derive character width in bytes instead of assuming ASCII encoding of 1 byte per char.

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/rulex
Introduced in: 0.0.0-0Fixed in: 0.4.3

Upgrade rulex to 0.4.3 or newer (ecosystem crates.io).

References