VDB
Sign up
HIGH

GHSA-xp3w-r5p5-63rr

rust-openssl has undefined behavior in X509Ref::ocsp_responders for certificates with non-UTF-8 OCSP URLs

Details

`X509Ref::ocsp_responders` returns OCSP responder URLs from a certificate's AIA extension as `OpensslString`, whose `Deref<Target = str>` wraps the raw bytes with `str::from_utf8_unchecked`. OpenSSL does not enforce that the underlying IA5String is ASCII, so a certificate with non-UTF-8 bytes in its OCSP accessLocation causes safe Rust code to construct a `&str` that violates the UTF-8 invariant — resulting in undefined behavior.

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/openssl
Introduced in: 0.9.7Fixed in: 0.10.79

Upgrade openssl to 0.10.79 or newer (ecosystem crates.io).

References