VDB
Sign up
HIGH7.5

GHSA-v5r6-6r3c-wqxc

Memory exhaustion in asn1_der

Details

An issue was discovered in the asn1_der crate before 0.6.2 for Rust. Attackers can trigger memory exhaustion by supplying a large value in a length field.

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/asn1_der
Introduced in: 0Fixed in: 0.6.2

Upgrade asn1_der to 0.6.2 or newer (ecosystem crates.io).

References