Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8rgq-m2pm-jvmg

Опубликовано: 26 янв. 2026
Источник: github
Github: Прошло ревью
CVSS4: 5.5

Описание

Duplicate Advisory: gix-date can create non-utf8 string with TimeBuf::as_str

Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-6mw6-mj76-grwc. This link is maintained to preserve external references.

Original Description

A flaw was found in gix-date. The gix_date::parse::TimeBuf::as_str function can generate strings containing invalid non-UTF8 characters. This issue violates the internal safety invariants of the TimeBuf component, leading to undefined behavior when these malformed strings are subsequently processed. This could potentially result in application instability or other unforeseen consequences.

Пакеты

Наименование

gix-date

rust
Затронутые версииВерсия исправления

< 0.12.0

0.12.0

5.5 Medium

CVSS4

Дефекты

CWE-787

5.5 Medium

CVSS4

Дефекты

CWE-787