VDB
Sign up
—

RUSTSEC-2023-0044

`openssl` `X509VerifyParamRef::set_host` buffer over-read

Details

When this function was passed an empty string, `openssl` would attempt to call `strlen` on it, reading arbitrary memory until it reached a NUL byte.

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/openssl
Introduced in: 0.0.0-0Fixed in: 0.10.55

Upgrade openssl to 0.10.55 or newer (ecosystem crates.io).

References