VDB
Sign up
HIGH

GHSA-ghm9-cr32-g9qj

rust-openssl: rustMdCtxRef::digest_final() writes past caller buffer with no length check

Details

`EVP_DigestFinal()` always writes `EVP_MD_CTX_size(ctx)` to the `out` buffer. If `out` is smaller than that, `MdCtxRef::digest_final()` writes past its end, usually corrupting the stack. This is reachable from safe Rust.

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/openssl
Introduced in: 0.10.39Fixed in: 0.10.78

Upgrade openssl to 0.10.78 or newer (ecosystem crates.io).

References