PT-2024-40916 · Unknown · Alloy-Json-Abi
Published
2024-07-30
·
Updated
2024-07-30
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions
alloy-json-abi versions prior to the version containing commit 4790c47
Description
The issue arises from improper handling of malformatted JSON ABI strings by the
alloy-json-abi crate. Specifically, the JsonAbi::parse method can be exploited to cause a stack overflow when processing specially crafted input, potentially leading to a denial of service due to application crashes.Recommendations
For versions prior to the one containing commit 4790c47, update to a version that includes the fix from commit 4790c47 to resolve the issue.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alloy-Json-Abi