VDB
Sign up
—

RUSTSEC-2022-0030

Stack overflow during recursive expression parsing

Details

When parsing untrusted rulex expressions, the stack may overflow, possibly enabling a Denial of Service attack. This happens when parsing an expression with several hundred levels of nesting, causing the process to abort immediately.

The flaw was corrected in commits `60aa2dc03a` by adding a check to recursion depth.

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/rulex
Introduced in: 0.0.0-0Fixed in: 0.4.3

Upgrade rulex to 0.4.3 or newer (ecosystem crates.io).

References