When parsing untrusted rulex expressions, the stack may overflow, possibly enabling a Denial of Service attack. This happens when parsing an expression with several hundred levels of nesting, causing the process to abort immediately.
This is a security concern for you, if
The crash is fixed in version 0.4.3. Affected users are advised to update to this version.
None.
If you have any questions or comments about this advisory:
Credit for finding these bugs goes to
{
"cwe_ids": [
"CWE-674"
],
"github_reviewed": true,
"github_reviewed_at": "2022-06-22T17:52:51Z",
"nvd_published_at": "2022-06-27T23:15:00Z",
"severity": "MODERATE"
}