RUSTSEC-2023-0004

Source
https://rustsec.org/advisories/RUSTSEC-2023-0004
Import Source
https://github.com/rustsec/advisory-db/blob/osv/crates/RUSTSEC-2023-0004.json
JSON Data
https://api.test.osv.dev/v1/vulns/RUSTSEC-2023-0004
Aliases
Published
2023-01-09T12:00:00Z
Modified
2023-11-01T05:01:09.927821Z
Summary
bzip2 Denial of Service (DoS)
Details

Working with specific payloads can cause a Denial of Service (DoS) vector.

Both Decompress and Compress implementations can enter into infinite loops given specific payloads entered that trigger it.

The issue is described in great detail in the bzip2 repository issue.

Thanks to bjrjk for finding and providing the patch for the issue and the maintainer responsibly responding to release a fix quickly.

Users who use the crate with untrusted data should update the bzip2 to 0.4.4.

Database specific
{
    "license": "CC0-1.0"
}
References

Affected packages

crates.io / bzip2

Package

Affected ranges

Type
SEMVER
Events
Introduced
0.0.0-0
Fixed
0.4.4

Ecosystem specific

{
    "affected_functions": null,
    "affects": {
        "os": [],
        "functions": [],
        "arch": []
    }
}

Database specific

{
    "cvss": null,
    "informational": null,
    "categories": [
        "denial-of-service"
    ]
}