This project might be open to known security vulnerabilities, which can be prevented by tightening the version range of affected dependencies. Find detailed information at the bottom.

Crate rocksdb

Dependencies

(1 total, all up-to-date)

CrateRequiredLatestStatus
 libc^0.2.110.2.171up to date

Dev dependencies

(4 total, 2 outdated)

CrateRequiredLatestStatus
 crc^1.83.2.1out of date
 lazy_static^1.4.01.5.0up to date
 rand^0.70.9.0out of date
 tempfile^3.13.19.1up to date

Crate librocksdb_sys

Dependencies

(7 total, 1 outdated, 1 possibly insecure)

CrateRequiredLatestStatus
 bzip2-sys^0.1.110.1.13+1.0.8up to date
 libc^0.2.110.2.171up to date
 libz-sys^1.11.1.22up to date
 openssl-sys^0.9.540.9.106up to date
 zstd-sys^2.0.12.0.15+zstd.1.5.7up to date
 lz4-sys ⚠️^1.91.11.1+lz4-1.10.0maybe insecure
 tikv-jemalloc-sys^0.5.00.6.0+5.3.0-1-ge13ca993e8ccb9ba9847cc330696e02839f328f7out of date

Dev dependencies

(1 total, all up-to-date)

CrateRequiredLatestStatus
 tempfile^3.13.19.1up to date

Build dependencies

(3 total, 1 outdated)

CrateRequiredLatestStatus
 cc^1.0.31.2.17up to date
 cmake^0.10.1.54up to date
 bindgen^0.650.71.1out of date

Crate libtitan_sys

Dependencies

(5 total, 1 possibly insecure)

CrateRequiredLatestStatus
 bzip2-sys^0.1.80.1.13+1.0.8up to date
 libc^0.2.110.2.171up to date
 libz-sys^1.11.1.22up to date
 zstd-sys^2.0.12.0.15+zstd.1.5.7up to date
 lz4-sys ⚠️^1.91.11.1+lz4-1.10.0maybe insecure

Build dependencies

(2 total, all up-to-date)

CrateRequiredLatestStatus
 cc^1.0.31.2.17up to date
 cmake^0.10.1.54up to date

Security Vulnerabilities

lz4-sys: Memory corruption in liblz4

RUSTSEC-2022-0051

lz4-sys up to v1.9.3 bundles a version of liblz4 that is vulnerable to CVE-2021-3520.

Attackers could craft a payload that triggers an integer overflow upon decompression, causing an out-of-bounds write.

The flaw has been corrected in version v1.9.4 of liblz4, which is included in lz4-sys 1.9.4.