Hi all,

(This was announced in various places early Monday but I forgot to send it
here -- doh!)

I discovered a vulnerability in Cap'n Proto C++. It appears to affect only
32-bit builds, seemingly only when built with Apple's compiler, and I think
it's only a DoS -- but my analysis could be wrong on any of these points.

I've released version 0.5.3.1 with the fix.

Details: https://github.com/sandstorm-io/capnproto/blob/master/
security-advisories/2017-04-17-0-apple-clang-elides-bounds-check.md

-Kenton

-- 
You received this message because you are subscribed to the Google Groups 
"Cap'n Proto" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to capnproto+unsubscr...@googlegroups.com.
Visit this group at https://groups.google.com/group/capnproto.

Reply via email to