—
RUSTSEC-2025-0140
Non-utf8 String can be created with `TimeBuf::as_str`
Details
The function `gix_date::parse::TimeBuf::as_str` can create an illegal string containing non-utf8 characters. This violates the safety invariant of `TimeBuf` and can lead to undefined behavior when consuming the string.
The bug can be prevented by adding `str::from_utf8` to the function `TimeBuf::write`.
Are you affected?
Enter the version of the package you're using.
Affected packages
crates.io/gix-date
Introduced in:
0.0.0-0Fixed in: 0.12.0Upgrade gix-date to 0.12.0 or newer (ecosystem crates.io).