This project contains known security vulnerabilities. Find detailed information at the bottom.

Crate dqcsim

Dependencies

(28 total, 19 outdated, 1 insecure)

CrateRequiredLatestStatus
 ansi_term^0.110.12.1out of date
 backtrace^0.30.3.76up to date
 clap^2.334.6.7out of date
 crossbeam-channel^0.30.5.17out of date
 failure^0.10.1.8up to date
 git-testament^0.10.2.6out of date
 humantime^1.22.4.0out of date
 ipc-channel^0.120.23.0out of date
 is_executable^0.11.0.6out of date
 lazy_static^1.31.5.0up to date
 libc^0.20.2.189up to date
 named_type^0.20.2.2up to date
 named_type_derive^0.20.2.2up to date
 num-complex^0.20.4.6out of date
 pathdiff^0.10.2.3out of date
 rand^0.60.10.3out of date
 rand_chacha^0.10.10.0out of date
 ref_thread_local^0.00.1.1out of date
 serde^1.01.0.229up to date
 serde-transcode^1.11.1.1up to date
 serde_cbor ⚠️^0.90.11.2insecure
 serde_json^1.01.0.151up to date
 serde_yaml^0.80.9.34+deprecatedout of date
 structopt^0.20.3.26out of date
 strum^0.150.28.0out of date
 strum_macros^0.150.28.0out of date
 term^0.51.2.1out of date
 whoami^0.52.1.3out of date

Security Vulnerabilities

serde_cbor: Flaw in CBOR deserializer allows stack overflow

RUSTSEC-2019-0025

Affected versions of this crate did not properly check if semantic tags were nested excessively during deserialization.

This allows an attacker to craft small (< 1 kB) CBOR documents that cause a stack overflow.

The flaw was corrected by limiting the allowed number of nested tags.