ppmd-rust is vulnerable to Heap-based Buffer Overflow
81
High Risk
The PPMd8 decoder in ppmd-rust mishandles model-restoration bookkeeping, turning an inconsistent model state directly into raw heap pointer arithmetic with no bounds or tag check. A crafted PPMd-compressed stream, such as a ZIP entry using compression method 98 whose restoration method does not match the one the encoder used, drives the decoder into the cut_off reduction path with corrupt accounting. This produces out-of-bounds heap reads and writes, including an oversized unit copy and a write through a freed pointer, corrupting memory during routine decompression of untrusted input. The fix corrects the frequency accumulation, flag handling, stats relocation copy size, successor write cursor, and restart-guard accounting so the decoder stays inside the model arena.
You are affected if you are using a version that falls within the vulnerable range and you decompress untrusted PPMd-compressed data, such as ZIP entries using compression method 98.
ppmd-rust is vulnerable to Heap-based Buffer Overflow in versions 1.1.1 - 1.4.0.
Upgrade the ppmd-rust library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.