VDB
Sign up
MEDIUM

GHSA-r6v5-fh4h-64xc

time vulnerable to stack exhaustion Denial of Service attack

Details

### Impact

When user-provided input is provided to any type that parses with the RFC 2822 format, a denial of service attack via stack exhaustion is possible. The attack relies on formally deprecated and rarely-used features that are part of the RFC 2822 format used in a malicious manner. Ordinary, non-malicious input will never encounter this scenario.

### Patches

A limit to the depth of recursion was added in v0.3.47. From this version, an error will be returned rather than exhausting the stack.

### Workarounds

Limiting the length of user input is the simplest way to avoid stack exhaustion, as the amount of the stack consumed would be at most a factor of the length of the input.

Alternatively, avoiding the format altogether would also ensure that the vulnerability is not encountered. To do this, add

```toml disallowed-types = ["time::format_description::well_known::Rfc2822"] ```

to your `clippy.toml` file. This will trigger the `clippy::disallowed_types` lint, which is warn-by-default and can be explicitly denied.

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/time
Introduced in: 0.3.6Fixed in: 0.3.47

Upgrade time to 0.3.47 or newer (ecosystem crates.io).

References