This project might be open to known security vulnerabilities, which can be prevented by tightening the version range of affected dependencies. Find detailed information at the bottom.

Crate rdkafka-sys

Dependencies

(5 total, 1 outdated, 1 possibly insecure)

CrateRequiredLatestStatus
 libc^0.2.650.2.153up to date
 libz-sys^1.01.1.16up to date
 lz4-sys ⚠️^1.8.31.9.4maybe insecure
 openssl-sys^0.9.480.9.102up to date
 zstd-sys^1.4.152.0.10+zstd.1.5.6out of date

Security Vulnerabilities

lz4-sys: Memory corruption in liblz4

RUSTSEC-2022-0051

lz4-sys up to v1.9.3 bundles a version of liblz4 that is vulnerable to CVE-2021-3520.

Attackers could craft a payload that triggers an integer overflow upon decompression, causing an out-of-bounds write.

The flaw has been corrected in version v1.9.4 of liblz4, which is included in lz4-sys 1.9.4.