—
RUSTSEC-2023-0004
bzip2 Denial of Service (DoS)
Details
Working with specific payloads can cause a Denial of Service (DoS) vector.
Both `Decompress` and `Compress` implementations can enter into infinite loops given specific payloads entered that trigger it.
The issue is described in great detail in the [bzip2 repository issue](https://github.com/alexcrichton/bzip2-rs/pull/86).
Thanks to bjrjk for finding and providing the patch for the issue and the maintainer responsibly responding to release a fix quickly.
Users who use the crate with untrusted data should update the `bzip2` to 0.4.4.
Are you affected?
Enter the version of the package you're using.
Affected packages
crates.io/bzip2
Introduced in:
0.0.0-0Fixed in: 0.4.4Upgrade bzip2 to 0.4.4 or newer (ecosystem crates.io).