GHSA-gpcv-p28p-fv2p
odoh-rs's Invalid Slice Split Results in Server Panic
Details
A vulnerability was discovered in the odoh-rs rust crate that stems from faulty logic during the parsing of encrypted queries. This issue specifically occurs when processing encrypted query data received from remote clients.
### Impact An attacker with knowledge of this vulnerability could craft and send specially designed encrypted queries to targeted ODOH servers running with odoh-rs. Upon successful exploitation, the server will crash abruptly, disrupting its normal operation and rendering the service temporarily unavailable.
### Patches Users are encouraged to update their odoh-rs's rust crate to v1.0.2.
Are you affected?
Enter the version of the package you're using.
Affected packages
0Fixed in: 1.0.2Upgrade odoh-rs to 1.0.2 or newer (ecosystem crates.io).
References
- https://github.com/cloudflare/odoh-rs/security/advisories/GHSA-gpcv-p28p-fv2p[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2023-3766[ADVISORY]
- https://github.com/cloudflare/odoh-rs/pull/28[WEB]
- https://github.com/cloudflare/odoh-rs/commit/c1bc4ed71dcc9842b7dc1ea26f278f105074bbaa[WEB]
- https://github.com/cloudflare/odoh-rs[PACKAGE]
- https://rustsec.org/advisories/RUSTSEC-2023-0095.html[WEB]