Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

RUSTSEC-2022-0048: xml-rs is Unmaintained #4951

Closed
github-actions bot opened this issue Aug 16, 2022 · 2 comments
Closed

RUSTSEC-2022-0048: xml-rs is Unmaintained #4951

github-actions bot opened this issue Aug 16, 2022 · 2 comments

Comments

@github-actions
Copy link
Contributor

xml-rs is Unmaintained

Details
Status unmaintained
Package xml-rs
Version 0.8.4
URL https://github.com/netvl/xml-rs/issues
Date 2022-01-26

xml-rs is a XML parser has open issues around parsing including integer
overflows / panics that may or may not be an issue with untrusted data.

Together with these open issues with Unmaintained status xml-rs
may or may not be suited to parse untrusted data.

Alternatives

See advisory page for additional details.

@FabianLars
Copy link
Member

netvl/xml-rs#221

@ozgunozerk
Copy link

ozgunozerk commented Oct 6, 2022

ebarnard/rust-plist#68
I think the sole cause for the quick-xml dependency is from plist dependency. Above is the issue to replace xml-rs with quick-xml in plist

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
Status: 📬Proposal
Development

No branches or pull requests

2 participants