David Renshaw, the author of the Rust implementation of Cap’n Proto, discovered a security vulnerability affecting both the C++ and Rust implementations of Cap’n Proto. The vulnerability was discovered using fuzzing. In theory, the vulnerability could lead to out-of-bounds reads which could cause crashes or perhaps exfiltration of memory.
CVE-2022-46149: Possible out-of-bounds read related to list-of-pointers
calendar_today
November 30, 2022
domain
capn-proto