VDB
Sign up
MEDIUM6.0

GHSA-cf4g-fcf8-3cr9

`pnet_packet` buffer overrun in `set_payload` setters

Details

As indicated by this [issue](https://github.com/libpnet/libpnet/issues/449#issuecomment-663355987), a buffer overrun is possible in the `set_payload` setter of the various mutable "Packet" struct setters. The offending `set_payload` functions were defined within the struct `impl` blocks in earlier versions of the package, and later by the `packet` macro.

Fixed in the `packet` macro by [this](https://github.com/libpnet/libpnet/pull/455) PR.

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/pnet_packet
Introduced in: 0Fixed in: 0.27.2

Upgrade pnet_packet to 0.27.2 or newer (ecosystem crates.io).

References