You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Stack overflow in rustc_serialize when parsing deeply nested JSON
Details
Package
rustc-serialize
Version
0.3.24
Date
2022-01-01
When parsing JSON using json::Json::from_str, there is no limit to the depth of the stack, therefore deeply nested objects can cause a stack overflow, which aborts the process.
rustc-serialize
0.3.24
When parsing JSON using
json::Json::from_str
, there is no limit to the depth of the stack, therefore deeply nested objects can cause a stack overflow, which aborts the process.Example code that triggers the vulnerability is
serde is recommended as a replacement to rustc_serialize.
See advisory page for additional details.
The text was updated successfully, but these errors were encountered: