{"id":"GHSA-8v9w-p43c-r885","summary":"Reachable Assertion in rulex","details":"### Impact\nWhen parsing untrusted rulex expressions, rulex may crash, possibly enabling a Denial of Service attack. This happens when the expression contains a multi-byte UTF-8 code point in a string literal or after a backslash, because rulex tries to slice into the code point and panics as a result.\n\nThis is a security concern for you, if\n- your service parses untrusted rulex expressions (expressions provided by an untrusted user), and\n- your service becomes unavailable when the thread running rulex panics.\n\n### Patches\nThe crashes are fixed in version **0.4.3**. Affected users are advised to update to this version.\n\n### Workarounds\nYou can use `catch_unwind` to recover from panics.\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Open an issue in [rulex](https://github.com/rulex-rs/rulex/issues)\n* Email me at [ludwig.stecher@gmx.de](mailto:ludwig.stecher@gmx.de)\n\n### Credits\n\nCredit for finding these bugs goes to\n\n- [cargo fuzz](https://github.com/rust-fuzz/cargo-fuzz) and [afl.rs](https://github.com/rust-fuzz/afl.rs)\n- [evanrichter](https://github.com/evanrichter)\n- [ForAllSecure Mayhem](https://forallsecure.com/)","aliases":["CVE-2022-31100","RUSTSEC-2022-0031"],"modified":"2023-11-01T04:58:57.791860Z","published":"2022-06-21T20:12:15Z","database_specific":{"cwe_ids":["CWE-617"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2022-06-21T20:12:15Z","nvd_published_at":"2022-06-27T22:15:00Z"},"references":[{"type":"WEB","url":"https://github.com/rulex-rs/rulex/security/advisories/GHSA-8v9w-p43c-r885"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-31100"},{"type":"WEB","url":"https://github.com/rulex-rs/rulex/commit/fac6d58b25c6f9f8c0a6cdc4dec75b37b219f1d6"},{"type":"PACKAGE","url":"https://github.com/rulex-rs/rulex"},{"type":"WEB","url":"https://rustsec.org/advisories/RUSTSEC-2022-0031.html"}],"affected":[{"package":{"name":"rulex","ecosystem":"crates.io","purl":"pkg:cargo/rulex"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.4.3"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/06/GHSA-8v9w-p43c-r885/GHSA-8v9w-p43c-r885.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}