VDB
Sign up
—

RUSTSEC-2023-0004

bzip2 Denial of Service (DoS)

Details

Working with specific payloads can cause a Denial of Service (DoS) vector.

Both `Decompress` and `Compress` implementations can enter into infinite loops given specific payloads entered that trigger it.

The issue is described in great detail in the [bzip2 repository issue](https://github.com/alexcrichton/bzip2-rs/pull/86).

Thanks to bjrjk for finding and providing the patch for the issue and the maintainer responsibly responding to release a fix quickly.

Users who use the crate with untrusted data should update the `bzip2` to 0.4.4.

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/bzip2
Introduced in: 0.0.0-0Fixed in: 0.4.4

Upgrade bzip2 to 0.4.4 or newer (ecosystem crates.io).

References