UbuntuUpdates.org

Package "librust-regex-dev"

Name: librust-regex-dev

Description:

Regular expressions for Rust - Rust source code

Latest version: 1.2.1-3ubuntu0.1
Release: focal (20.04)
Level: security
Repository: universe
Head package: rust-regex
Homepage: https://github.com/rust-lang/regex

Links


Download "librust-regex-dev"


Other versions of "librust-regex-dev" in Focal

Repository Area Version
base universe 1.2.1-3
updates universe 1.2.1-3ubuntu0.1

Changelog

Version: 1.2.1-3ubuntu0.1 2022-09-14 10:06:19 UTC

  rust-regex (1.2.1-3ubuntu0.1) focal-security; urgency=medium

  * SECURITY UPDATE: fix denial-of-service bug in compiler (LP: #1977694)
    - debian/patches/CVE-2022-24713-pre.patch: support empty patterns
    in src/compile.rs.
    - debian/patches/CVE-2022-24713-pre2.patch: account for Unicode
    class size in regex compilation error in src/compile.rs.
    - debian/patches/CVE-2022-24713.patch: adding a fake amount of
    memory every time we compile an empty sub-expression in
    src/compile.rs.
    - CVE-2022-24713

 -- David Fernandez Gonzalez <email address hidden> Tue, 21 Jun 2022 09:14:36 -0500

1977694 [CVE-2022-24713] Denial of service in compiler with rust-regex
CVE-2022-24713 regex is an implementation of regular expressions for the Rust language. The regex crate features built-in mitigations to prevent denial of service a



About   -   Send Feedback to @ubuntu_updates