This project contains known security vulnerabilities. Find detailed information at the bottom.

Crate pyoxidizer

Dependencies

(32 total, 19 outdated, 1 insecure)

CrateRequiredLatestStatus
 byteorder^1.21.5.0up to date
 cargo_toml^0.61.0.1out of date
 cc^1.01.4.6up to date
 clap^2.324.6.7out of date
 encoding_rs^0.80.8.41up to date
 git2^0.90.21.0out of date
 glob^0.30.3.4up to date
 goblin^0.00.10.7out of date
 handlebars^1.16.4.4out of date
 hex^0.30.4.3out of date
 itertools^0.80.15.0out of date
 lazy_static^1.31.5.0up to date
 libc^0.20.2.189up to date
 regex^11.13.1up to date
 reqwest^0.90.13.5out of date
 rustc_version^0.20.4.1out of date
 semver^0.91.0.28out of date
 serde^1.01.0.229up to date
 serde_cbor ⚠️^0.90.11.2insecure
 serde_json^1.01.0.151up to date
 sha2^0.80.11.0out of date
 slog^2.42.8.2up to date
 tar^0.40.4.46up to date
 tempdir^0.30.3.7up to date
 toml^0.51.1.6+spec-1.1.0out of date
 url^1.72.5.8out of date
 uuid^0.71.26.1out of date
 version-compare^0.00.2.1out of date
 walkdir^22.5.0up to date
 xml-rs^0.81.0.0out of date
 zip^0.58.6.0out of date
 zstd^0.40.14.0out of date

Security Vulnerabilities

serde_cbor: Flaw in CBOR deserializer allows stack overflow

RUSTSEC-2019-0025

Affected versions of this crate did not properly check if semantic tags were nested excessively during deserialization.

This allows an attacker to craft small (< 1 kB) CBOR documents that cause a stack overflow.

The flaw was corrected by limiting the allowed number of nested tags.