Receiving QUIC frames containing a frame with unknown frame type could lead to a panic. Unfortunately this is issue was not found by our fuzzing infrastructure.
Thanks to the QUIC Tester research group for reporting this issue.
equalitie / ouisync
This project might be open to known security vulnerabilities, which can be prevented by tightening the version range of affected dependencies. Find detailed information at the bottom.
ouisync-bridge
(6 total, 5 outdated)
Crate | Required | Latest | Status |
---|---|---|---|
ansi_term | ^0.12.1 | 0.12.1 | up to date |
file-rotate | ^0.7.5 | 0.8.0 | out of date |
indexmap | ^1.9.3 | 2.8.0 | out of date |
pem | ^2.0.1 | 3.0.5 | out of date |
tokio-tungstenite | ^0.20.0 | 0.26.2 | out of date |
webpki-roots | ^0.22.6 | 0.26.8 | out of date |
ouisync-cli
(7 total, 5 outdated)
Crate | Required | Latest | Status |
---|---|---|---|
bytes | ^1.4.0 | 1.10.1 | up to date |
dirs | ^4.0.0 | 6.0.0 | out of date |
hyper | ^0.14.27 | 1.6.0 | out of date |
hyper-rustls | ^0.24.1 | 0.27.5 | out of date |
interprocess | ^1.2.1 | 2.2.3 | out of date |
maxminddb | ^0.23.0 | 0.25.0 | out of date |
walkdir | ^2.3.3 | 2.5.0 | up to date |
(3 total, all up-to-date)
Crate | Required | Latest | Status |
---|---|---|---|
anyhow | ^1.0.57 | 1.0.97 | up to date |
backoff | ^0.4.0 | 0.4.0 | up to date |
hex | ^0.4.3 | 0.4.3 | up to date |
deadlock
No external dependencies! 🙌
ouisync-ffi
(1 total, all up-to-date)
Crate | Required | Latest | Status |
---|---|---|---|
hex | ^0.4.3 | 0.4.3 | up to date |
ouisync
(29 total, 9 outdated)
Crate | Required | Latest | Status |
---|---|---|---|
argon2 | ^0.4.1 | 0.5.3 | out of date |
async-recursion | ^1.0.0 | 1.1.1 | up to date |
backoff | ^0.4.0 | 0.4.0 | up to date |
base64 | ^0.13.0 | 0.22.1 | out of date |
bincode | ^1.3 | 2.0.1 | out of date |
blake3 | ^1.5.0 | 1.6.1 | up to date |
chacha20 | ^0.9.1 | 0.9.1 | up to date |
crossbeam-channel | ^0.5.8 | 0.5.14 | up to date |
ed25519-dalek | ^2.0 | 2.1.1 | up to date |
either | ^1.6.1 | 1.15.0 | up to date |
generic-array | ^0.14.5 | 1.2.0 | out of date |
hex | ^0.4.3 | 0.4.3 | up to date |
if-watch | ^3.2.0 | 3.2.1 | up to date |
include_dir | ^0.7.3 | 0.7.4 | up to date |
indexmap | ^1.9.3 | 2.8.0 | out of date |
lru | ^0.11.0 | 0.13.0 | out of date |
noise-protocol | ^0.2.0 | 0.2.0 | up to date |
noise-rust-crypto | ^0.6.1 | 0.6.2 | up to date |
parse-size | ^1.0.0 | 1.1.0 | up to date |
pin-project-lite | ^0.2.13 | 0.2.16 | up to date |
ref-cast | ^1.0.14 | 1.0.24 | up to date |
rupnp | ^1.1.0 | 2.0.0 | out of date |
slab | ^0.4.6 | 0.4.9 | up to date |
ssdp-client | ^1.0 | 2.0.0 | out of date |
subtle | ^2.5.0 | 2.6.1 | up to date |
twox-hash | ^1.6.3 | 2.1.0 | out of date |
urlencoding | ^2.1.0 | 2.1.3 | up to date |
vint64 | ^1.0.1 | 1.0.1 | up to date |
zeroize | ^1.6.0 | 1.8.1 | up to date |
(6 total, 2 outdated)
Crate | Required | Latest | Status |
---|---|---|---|
criterion | ^0.4 | 0.5.1 | out of date |
hdrhistogram | ^7.5.4 | 7.5.4 | up to date |
proptest | ^1.0 | 1.6.0 | up to date |
serde_test | ^1.0.176 | 1.0.177 | up to date |
similar-asserts | ^1.5.0 | 1.7.0 | up to date |
test-strategy | ^0.2.1 | 0.4.0 | out of date |
metrics_ext
(1 total, 1 outdated)
Crate | Required | Latest | Status |
---|---|---|---|
reqwest | ^0.11.23 | 0.12.12 | out of date |
ouisync-net
(7 total, 3 outdated, 1 possibly insecure)
Crate | Required | Latest | Status |
---|---|---|---|
bytecodec | ^0.4.15 | 0.4.15 | up to date |
bytes | ^1.1.0 | 1.10.1 | up to date |
quinn | ^0.10.2 | 0.11.6 | out of date |
quinn-proto ⚠️ | ^0.10.2 | 0.11.9 | out of date |
socket2 | ^0.5.7 | 0.5.8 | up to date |
stun_codec | ^0.3.4 | 0.3.5 | up to date |
thiserror | ^1.0.31 | 2.0.12 | out of date |
ouisync-rand
(2 total, 1 outdated)
Crate | Required | Latest | Status |
---|---|---|---|
rand | ^0.8.5 | 0.9.0 | out of date |
siphasher | ^1.0.0 | 1.0.1 | up to date |
scoped_task
No external dependencies! 🙌
state_monitor
(1 total, 1 outdated)
Crate | Required | Latest | Status |
---|---|---|---|
indexmap | ^1.9.3 | 2.8.0 | out of date |
ouisync-tracing-fmt
(1 total, all up-to-date)
Crate | Required | Latest | Status |
---|---|---|---|
ansi_term | ^0.12.1 | 0.12.1 | up to date |
ouisync-bindgen
(2 total, 1 outdated)
Crate | Required | Latest | Status |
---|---|---|---|
heck | ^0.4.1 | 0.5.0 | out of date |
syn | ^2.0.33 | 2.0.100 | up to date |
ouisync-utilities
(4 total, 1 outdated)
Crate | Required | Latest | Status |
---|---|---|---|
futures-util | ^0.3.21 | 0.3.31 | up to date |
env_logger | ^0.9.0 | 0.11.7 | out of date |
log | ^0.4.17 | 0.4.26 | up to date |
structopt | ^0.3.26 | 0.3.26 | up to date |
ouisync-repogen
No external dependencies! 🙌
ouisync-repo-tool
No external dependencies! 🙌
ouisync-stress-test
No external dependencies! 🙌
stun-server-list
(1 total, 1 outdated)
Crate | Required | Latest | Status |
---|---|---|---|
reqwest | ^0.11.23 | 0.12.12 | out of date |
ouisync-swarm
(2 total, all up-to-date)
Crate | Required | Latest | Status |
---|---|---|---|
ctrlc | ^3.4.1 | 3.4.5 | up to date |
os_pipe | ^1.1.4 | 1.2.1 | up to date |
ouisync-protocol-analyzer
(1 total, all up-to-date)
Crate | Required | Latest | Status |
---|---|---|---|
chrono | ^0.4.31 | 0.4.40 | up to date |
ouisync-vfs
(2 total, all up-to-date)
Crate | Required | Latest | Status |
---|---|---|---|
camino | ^1.0.9 | 1.1.9 | up to date |
slab | ^0.4.6 | 0.4.9 | up to date |
(4 total, 3 outdated)
Crate | Required | Latest | Status |
---|---|---|---|
criterion | ^0.4 | 0.5.1 | out of date |
proptest | ^1.0 | 1.6.0 | up to date |
rand | ^0.8.5 | 0.9.0 | out of date |
test-strategy | ^0.2.1 | 0.4.0 | out of date |
benchtool
(2 total, all up-to-date)
Crate | Required | Latest | Status |
---|---|---|---|
comfy-table | ^7.1.1 | 7.1.4 | up to date |
indicatif | ^0.17.8 | 0.17.11 | up to date |
quinn-proto
: Denial of service in Quinn serversReceiving QUIC frames containing a frame with unknown frame type could lead to a panic. Unfortunately this is issue was not found by our fuzzing infrastructure.
Thanks to the QUIC Tester research group for reporting this issue.