VDB
Sign up
—

RUSTSEC-2025-0140

Non-utf8 String can be created with `TimeBuf::as_str`

Details

The function `gix_date::parse::TimeBuf::as_str` can create an illegal string containing non-utf8 characters. This violates the safety invariant of `TimeBuf` and can lead to undefined behavior when consuming the string.

The bug can be prevented by adding `str::from_utf8` to the function `TimeBuf::write`.

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/gix-date
Introduced in: 0.0.0-0Fixed in: 0.12.0

Upgrade gix-date to 0.12.0 or newer (ecosystem crates.io).

References