RUSTSEC-2022-0068
out-of-bounds read possible when setting list-of-pointers
Details
If a message consumer expects data of type "list of pointers", and if the consumer performs certain specific actions on such data, then a message producer can cause the consumer to read out-of-bounds memory. This could trigger a process crash in the consumer, or in some cases could allow exfiltration of private in-memory data.
The C++ Cap'n Proto library is also affected by this bug. See the [advisory](https://github.com/capnproto/capnproto/tree/master/security-advisories/2022-11-30-0-pointer-list-bounds.md) on the main Cap'n Proto repo for a succinct description of the exact circumstances in which the problem can arise.
Are you affected?
Enter the version of the package you're using.
Affected packages
0.0.0-0Fixed in: 0.13.7Upgrade capnp to 0.13.7 or newer (ecosystem crates.io).
References
- https://crates.io/crates/capnp[PACKAGE]
- https://rustsec.org/advisories/RUSTSEC-2022-0068.html[ADVISORY]
- https://github.com/capnproto/capnproto/tree/master/security-advisories/2022-11-30-0-pointer-list-bounds.md[WEB]
- https://dwrensha.github.io/capnproto-rust/2022/11/30/out_of_bounds_memory_access_bug.html[WEB]
- https://github.com/capnproto/capnproto/security/advisories/GHSA-qqff-4vw4-f6hx[ADVISORY]