-
Notifications
You must be signed in to change notification settings - Fork 375
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
parse_duration: parse
DoS through payloads with big exponent
#827
Conversation
It looks like the directory the advisory is inside of doesn't match the package name, i.e.:
|
b693157
to
45bee71
Compare
parse
denial of service through payloads with big exponentparse
DoS through payloads with big exponent
Fixed! |
Oh whoops, my bad, it looks like the name on crates.io has an underscore: https://crates.io/crates/parse_duration So: Sorry about that |
45bee71
to
5f2ce59
Compare
parse
DoS through payloads with big exponentparse
DoS through payloads with big exponent
Haha; fixed! :) |
Hmm the linter says it should be |
Co-authored-by: Tony Arcieri <bascule@gmail.com>
If the crate developers want to report this, I don't see why not include this advisory. |
Just to be clear: I am not the |
No description provided.