VDB
Sign up
LOW

GHSA-v363-rrf2-5fmj

ferris-says has undefined behavior when not using UTF-8

Details

Affected versions receive a `&[u8]` from the caller through a safe API, and pass it directly to the unsafe `str::from_utf8_unchecked` function.

The behavior of `ferris_says::say` is undefined if the bytes from the caller don't happen to be valid UTF-8.

The flaw was corrected in [ferris-says#21] by using the safe `str::from_utf8` instead, and returning an error on invalid input. However this fix has not yet been published to crates.io as a patch version for 0.2.

Separately, [ferris-says#32] has introduced a different API for version 0.3 which accepts input as `&str` rather than `&[u8]`, so is unaffected by this bug.

[ferris-says#21]: https://github.com/rust-lang/ferris-says/pull/21 [ferris-says#32]: https://github.com/rust-lang/ferris-says/pull/32

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/ferris-says
Introduced in: 0.1.2

No fixed version published yet for ferris-says. Pin to a known-safe version or switch to an alternative.

crates.io/ferris-says
Introduced in: 0.3.0Fixed in: 0.3.1

Upgrade ferris-says to 0.3.1 or newer (ecosystem crates.io).

References