Skip to content

Add advisory for index error in mp3-metadata #2294

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 1 commit into from
Apr 30, 2025

Conversation

llooFlashooll
Copy link
Contributor

No description provided.

@djc
Copy link
Contributor

djc commented Apr 28, 2025

@GuillaumeGomez r? Any thoughts?

@GuillaumeGomez
Copy link

Confirmed. I fixed the issue and added a regression test.

@djc
Copy link
Contributor

djc commented Apr 29, 2025

IMO it would be nice to have a bit more context around the actual issue -- how was the panic triggered (in terms of library semantics), ideally even adding affected function calls if possible. I don't think most of the audience will care that it was found via a fuzzer (except that it sort of diminishes the impact, I suppose, if it wasn't found in the real world), and that it was fixed is pretty obvious too.

@llooFlashooll
Copy link
Contributor Author

@djc You are right! I have updated more information for the advisory.

@djc djc merged commit 9364064 into rustsec:main Apr 30, 2025
1 check passed
@djc
Copy link
Contributor

djc commented Apr 30, 2025

Did some further editing. Thanks!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants