iotaledger / chronicle.rs

A framework for building IOTA permanodes
Apache License 2.0
73 stars 15 forks source link

RUSTSEC-2018-0006: Uncontrolled recursion leads to abort in deserialization #127

Closed github-actions[bot] closed 1 year ago

github-actions[bot] commented 1 year ago

Uncontrolled recursion leads to abort in deserialization

Details
Package yaml-rust
Version 0.3.5
URL https://github.com/chyh1990/yaml-rust/pull/109
Date 2018-09-17
Patched versions >=0.4.1

Affected versions of this crate did not prevent deep recursion while deserializing data structures.

This allows an attacker to make a YAML file with deeply nested structures that causes an abort while deserializing it.

The flaw was corrected by checking the recursion depth.

Note: clap 2.33 is not affected by this because it uses yaml-rust in a way that doesn't trigger the vulnerability. More specifically:

  1. The input to the YAML parser is always trusted - is included at compile time via include_str!.

  2. The nesting level is never deep enough to trigger the overflow in practice (at most 5).

See advisory page for additional details.