RUSTSEC-2023-0095
Dashboard / Vulnerabilities / RUSTSEC-2023-0095
RUSTSEC-2023-0095
Summary: Invalid Slice Split Results in Server Panic
Details: A vulnerability was discovered in the odoh-rs rust crate that stems from faulty logic during the parsing of encrypted queries. This issue specifically occurs when processing encrypted query data received from remote clients. ## Impact An attacker with knowledge of this vulnerability could craft and send specially designed encrypted queries to targeted ODOH servers running with odoh-rs. Upon successful exploitation, the server will crash abruptly, disrupting its normal operation and rendering the service temporarily unavailable. ## Patches Users are encouraged to update their odoh-rs's rust crate to v1.0.2.
References: https://crates.io/crates/odoh-rs, https://rustsec.org/advisories/RUSTSEC-2023-0095.html, https://github.com/cloudflare/odoh-rs/security/advisories/GHSA-gpcv-p28p-fv2p, https://github.com/cloudflare/odoh-rs/pull/28
Affected packages
Package
Name: odoh-rs
Purl: pkg:cargo/odoh-rs
Affected ranges
Type: SEMVER
Events:
