VDB
Sign up
MEDIUM5.9

GHSA-gpcv-p28p-fv2p

odoh-rs's Invalid Slice Split Results in Server Panic

Details

A vulnerability was discovered in the odoh-rs rust crate that stems from faulty logic during the parsing of encrypted queries. This issue specifically occurs when processing encrypted query data received from remote clients.

### Impact An attacker with knowledge of this vulnerability could craft and send specially designed encrypted queries to targeted ODOH servers running with odoh-rs. Upon successful exploitation, the server will crash abruptly, disrupting its normal operation and rendering the service temporarily unavailable.

### Patches Users are encouraged to update their odoh-rs's rust crate to v1.0.2.

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/odoh-rs
Introduced in: 0Fixed in: 1.0.2

Upgrade odoh-rs to 1.0.2 or newer (ecosystem crates.io).

References