An issue was discovered in the asn1_der crate before 0.6.2 for Rust. Attackers can trigger memory exhaustion by supplying a large value in a length field.
The product does not properly control the allocation and maintenance of a limited resource.
Link | Tags |
---|---|
https://rustsec.org/advisories/RUSTSEC-2019-0007.html | third party advisory |