Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2rxc-gjrp-vjhx

Опубликовано: 04 дек. 2024
Источник: github
Github: Прошло ревью

Описание

Unsoundness in anstream

When given a valid UTF8 string "ö\x1b😀", the function in crates/anstream/src/adapter/strip.rs will be confused. The UTF8 bytes are \xc3\xb6 then \x1b then \xf0\x9f\x98\x80.

When looping over "non-printable bytes" \x1b\xf0 will be considered as some non-printable sequence.

This will produce a broken str from the incorrectly segmented bytes via str::from_utf8_unchecked, and that should never happen.

Full credit goes to @Ralith who reviewed this code and asked @burakemir to follow up.

Пакеты

Наименование

anstream

rust
Затронутые версииВерсия исправления

< 0.6.8

0.6.8