Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

RUSTSEC-2023-0052: webpki: CPU denial of service in certificate path building #1098

Closed
github-actions bot opened this issue Aug 27, 2023 · 2 comments
Closed
Assignees
Milestone

Comments

@github-actions
Copy link

webpki: CPU denial of service in certificate path building

Details
Package webpki
Version 0.22.0
Date 2023-08-22

When this crate is given a pathological certificate chain to validate, it will
spend CPU time exponential with the number of candidate certificates at each
step of path building.

Both TLS clients and TLS servers that accept client certificate are affected.

This was previously reported in
<https://github.com/briansmith/webpki/issues/69> and re-reported recently
by Luke Malinowski.

rustls-webpki is a fork of this crate which contains a fix for this issue
and is actively maintained.

See advisory page for additional details.

@notmandatory
Copy link
Member

This will be fixed with #1183 since the latest versions of webpki require rust 1.61+.

@notmandatory notmandatory moved this to In Progress in BDK Wallet Nov 13, 2023
@notmandatory notmandatory added this to the 1.0.0-alpha.4 milestone Nov 13, 2023
@notmandatory notmandatory moved this from In Progress to Needs Review in BDK Wallet Nov 15, 2023
@notmandatory notmandatory self-assigned this Nov 15, 2023
@nondiremanuel
Copy link

@notmandatory should we close this issue since #1183 was merged?

@nondiremanuel nondiremanuel modified the milestones: 1.0.0-alpha.4, 1.0.0 Jan 6, 2024
@notmandatory notmandatory modified the milestones: 1.0.0, 1.0.0-alpha.3 Jan 8, 2024
@github-project-automation github-project-automation bot moved this from Needs Review to Done in BDK Wallet Jan 8, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
Archived in project
Development

No branches or pull requests

2 participants