Hi all,

(This was announced in various places early Monday but I forgot to send it
here -- doh!)

I discovered a vulnerability in Cap'n Proto C++. It appears to affect only
32-bit builds, seemingly only when built with Apple's compiler, and I think
it's only a DoS -- but my analysis could be wrong on any of these points.

I've released version 0.5.3.1 with the fix.

Details: https://github.com/sandstorm-io/capnproto/blob/master/
security-advisories/2017-04-17-0-apple-clang-elides-bounds-check.md

-Kenton

-- 
You received this message because you are subscribed to the Google Groups 
"Cap'n Proto" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
Visit this group at https://groups.google.com/group/capnproto.

Reply via email to