Skip to content

Add advisory for http-types: violated ASCII invariants#2923

Open
yilin0518 wants to merge 1 commit into
rustsec:mainfrom
yilin0518:http-types
Open

Add advisory for http-types: violated ASCII invariants#2923
yilin0518 wants to merge 1 commit into
rustsec:mainfrom
yilin0518:http-types

Conversation

@yilin0518
Copy link
Copy Markdown

Affected crate(s)

  • http-types(5,354,945downloads per crates.io)

Links to upstream issue(s) or PR(s)

Severity

Soundness issue: safe parsing bypasses the DNSKEY RDATA 16-bit length invariant, allowing construction of invalid records and violating new_unchecked safety preconditions, which can undermine memory safety assumptions.

Checklist

  • Advisory filename(s) starts with RUSTSEC-0000-0000 as the ID
  • date field is set to the public disclosure date
  • Contains a concise and descriptive title after advisory metadata
  • Asked maintainer(s) if publishing an advisory is appropriate

This repo is active, but the issue has no reply for more than two months. Although this crate has published new version, the ths same soundness issues exist.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant