VDB
Sign up
MEDIUM

GHSA-2226-4v3c-cff8

Stack overflow in rustc_serialize when parsing deeply nested JSON

Details

When parsing JSON using `json::Json::from_str`, there is no limit to the depth of the stack, therefore deeply nested objects can cause a stack overflow, which aborts the process.

Example code that triggers the vulnerability is

```rust fn main() { let _ = rustc_serialize::json::Json::from_str(&"[0,[".repeat(10000)); } ```

[serde](https://crates.io/crates/serde) is recommended as a replacement to rustc_serialize.

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/rustc-serialize
Introduced in: 0

No fixed version published yet for rustc-serialize. Pin to a known-safe version or switch to an alternative.

References