Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

base64 vulnerability (RUSTSEC-2017-0004) #65

Closed
oherrala opened this issue May 5, 2017 · 1 comment
Closed

base64 vulnerability (RUSTSEC-2017-0004) #65

oherrala opened this issue May 5, 2017 · 1 comment

Comments

@oherrala
Copy link

oherrala commented May 5, 2017

Apparently base64 crate is updated to version 0.5 in dac2274, but latest version in crates.io is still using the vulnerable crate.

ID: RUSTSEC-2017-0004
Crate: base64
Version: 0.2.1
Date: 2017-05-03
URL: marshallpierce/rust-base64@24ead98
Title: Integer overflow leads to heap-based buffer overflow in encode_config_buf
Solution: upgrade to: >= 0.5.2

@ctz
Copy link
Member

ctz commented May 6, 2017

0.6.0 is published now.

@ctz ctz closed this as completed May 6, 2017
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants