This project might be open to known security vulnerabilities, which can be prevented by tightening the version range of affected dependencies. Find detailed information at the bottom.

Crate libspeedb-sys

Dependencies

(6 total, 1 outdated, 1 possibly insecure)

CrateRequiredLatestStatus
 bzip2-sys^0.10.1.11+1.0.8up to date
 libc^0.20.2.158up to date
 libz-sys^1.11.1.20up to date
 lz4-sys ⚠️^1.91.11.0maybe insecure
 tikv-jemalloc-sys^0.50.6.0+5.3.0-1-ge13ca993e8ccb9ba9847cc330696e02839f328f7out of date
 zstd-sys^2.02.0.13+zstd.1.5.6up to date

Dev dependencies

(2 total, all up-to-date)

CrateRequiredLatestStatus
 const-cstr^0.30.3.0up to date
 uuid^1.01.10.0up to date

Security Vulnerabilities

lz4-sys: Memory corruption in liblz4

RUSTSEC-2022-0051

lz4-sys up to v1.9.3 bundles a version of liblz4 that is vulnerable to CVE-2021-3520.

Attackers could craft a payload that triggers an integer overflow upon decompression, causing an out-of-bounds write.

The flaw has been corrected in version v1.9.4 of liblz4, which is included in lz4-sys 1.9.4.