This project might be open to known security vulnerabilities, which can be prevented by tightening the version range of affected dependencies. Find detailed information at the bottom.

Crate rocksdb

Dependencies

(1 total, all up-to-date)

CrateRequiredLatestStatus
 libc^0.2.110.2.153up to date

Dev dependencies

(4 total, 2 outdated)

CrateRequiredLatestStatus
 crc^1.83.2.1out of date
 lazy_static^1.4.01.4.0up to date
 rand^0.70.8.5out of date
 tempfile^3.13.10.1up to date

Crate librocksdb_sys

Dependencies

(7 total, 1 possibly insecure)

CrateRequiredLatestStatus
 bzip2-sys^0.1.110.1.11+1.0.8up to date
 libc^0.2.110.2.153up to date
 libz-sys^1.11.1.16up to date
 openssl-sys^0.9.540.9.102up to date
 zstd-sys^2.0.12.0.10+zstd.1.5.6up to date
 lz4-sys ⚠️^1.91.9.4maybe insecure
 tikv-jemalloc-sys^0.5.00.5.4+5.3.0-patchedup to date

Dev dependencies

(1 total, all up-to-date)

CrateRequiredLatestStatus
 tempfile^3.13.10.1up to date

Build dependencies

(3 total, 1 outdated)

CrateRequiredLatestStatus
 cc^1.0.31.0.95up to date
 cmake^0.10.1.50up to date
 bindgen^0.650.69.4out of date

Crate libtitan_sys

Dependencies

(5 total, 1 possibly insecure)

CrateRequiredLatestStatus
 bzip2-sys^0.1.80.1.11+1.0.8up to date
 libc^0.2.110.2.153up to date
 libz-sys^1.11.1.16up to date
 zstd-sys^2.0.12.0.10+zstd.1.5.6up to date
 lz4-sys ⚠️^1.91.9.4maybe insecure

Build dependencies

(2 total, all up-to-date)

CrateRequiredLatestStatus
 cc^1.0.31.0.95up to date
 cmake^0.10.1.50up to date

Security Vulnerabilities

lz4-sys: Memory corruption in liblz4

RUSTSEC-2022-0051

lz4-sys up to v1.9.3 bundles a version of liblz4 that is vulnerable to CVE-2021-3520.

Attackers could craft a payload that triggers an integer overflow upon decompression, causing an out-of-bounds write.

The flaw has been corrected in version v1.9.4 of liblz4, which is included in lz4-sys 1.9.4.