Skip to content

Heap buffer overflow in APNSwiftSigner.sign(digest:)

Moderate
kylebrowning published GHSA-qh2w-vjxg-mjcg Jul 23, 2019 · 1 comment

Package

APNSwift (swift-nio, vapor, perfect, kitura)

Affected versions

1.0.0

Patched versions

1.0.1

Description

Impact

calling APNSwiftSigner.sign(digest:) is likely to result in a heap buffer overflow

Patches

This has been resolved in #32.
Users of APNSwift should upgrade to 1.0.1. from: "1.0.1" in package.swift

Workarounds

No

For more information

If you have any questions or comments about this advisory:

Severity

Moderate

CVE ID

CVE-2020-4068

Weaknesses

No CWEs