Add kamadak-exif DoS (#1411)

This commit is contained in:
pinkforest(she/her)
2022-09-08 20:51:34 +10:00
committed by GitHub
parent 7f6f544c39
commit 3834127c26

View File

@@ -0,0 +1,22 @@
```toml
[advisory]
id = "RUSTSEC-0000-0000"
package = "kamadak-exif"
date = "2021-01-04"
url = "https://github.com/kamadak/exif-rs/commit/1b05eab57e484cd7d576d4357b9cda7fdc57df8c"
categories = ["denial-of-service"]
cvss = "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
keywords = ["untrusted-data", "dos"]
aliases = ["CVE-2021-21235", "GHSA-px9g-8hgv-jvg2"]
[affected]
functions = { "kamadak_exif::Reader::read_from_container" = [">= 0.5.2, < 0.5.3"] }
[versions]
patched = [">= 0.5.3"]
unaffected = ["< 0.5.2"]
```
# kamadak-exif DoS with untrusted PNG data
Attacker crafted data can cause a infinite loop leading to DoS if used with untrusted data.