Affected version of this crate did not properly parse unknown fields when parsing a user-supplied input.
This allows an attacker to cause a stack overflow when parsing the mssage on untrusted data.
This project contains known security vulnerabilities. Find detailed information at the bottom.
record-query(26 total, 13 outdated, 1 insecure)
| Crate | Required | Latest | Status |
|---|---|---|---|
| ansi_term | ^0.12.1 | 0.12.1 | up to date |
| atty | ^0.2.13 | 0.2.14 | up to date |
| avro-rs | ^0.6.5 | 0.13.0 | out of date |
| csv | ^1.1.1 | 1.4.0 | up to date |
| directories | ^2.0.2 | 6.0.0 | out of date |
| dtoa | ^0.4.4 | 1.0.11 | out of date |
| env_logger | ^0.7.1 | 0.11.11 | out of date |
| failure | ^0.1.6 | 0.1.8 | up to date |
| glob | ^0.3.0 | 0.3.4 | up to date |
| itoa | ^0.4.4 | 1.0.18 | out of date |
| log | ^0.4.8 | 0.4.34 | up to date |
| nix | ^0.15.0 | 0.31.3 | out of date |
| ordered-float | ^1.0.2 | 5.5.0 | out of date |
| pest | ^2.1.2 | 2.9.2 | up to date |
| protobuf ⚠️ | ^2.8.1 | 3.7.2 | insecure |
| rmp | ^0.8.8 | 0.8.15 | up to date |
| rmpv | ^0.4.2 | 1.3.1 | out of date |
| serde | ^1.0.102 | 1.0.229 | up to date |
| serde-hjson | ^0.9.1 | 1.1.0 | out of date |
| serde-protobuf | ^0.8.1 | 0.8.2 | up to date |
| serde_cbor | ^0.10.2 | 0.11.2 | out of date |
| serde_json | ^1.0.41 | 1.0.151 | up to date |
| serde_yaml | ^0.8.11 | 0.9.34+deprecated | out of date |
| structopt | ^0.3.4 | 0.3.26 | up to date |
| toml | ^0.5.5 | 1.1.6+spec-1.1.0 | out of date |
| yaml-rust | ^0.4.3 | 0.4.5 | up to date |
protobuf: Crash due to uncontrolled recursion in protobuf crateAffected version of this crate did not properly parse unknown fields when parsing a user-supplied input.
This allows an attacker to cause a stack overflow when parsing the mssage on untrusted data.