VDB
Sign up
LOW

GHSA-xmgf-hq76-4vx2

rust-opennssl has an Out-of-bounds read in PEM password callback when returning an oversized length

Details

The `*_from_pem_callback` APIs did not validate the length returned by the user's callback. A password callback that returns a value larger than the buffer it was given can cause some versions of OpenSSL to over-read this buffer. OpenSSL 3.x is not affected by this.

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/openssl
Introduced in: 0.9.0Fixed in: 0.10.78

Upgrade openssl to 0.10.78 or newer (ecosystem crates.io).

References