En APNSwift 1.0.0, appelant APNSwiftSigner.sign (digest 🙂 est susceptible d’entraîner un débordement de mémoire tampon. Ceci a été corrigé dans la version 1.0.1.
https://github.com/kylebrowning/APNSwift/security/advisories/GHSA-qh2w-vjxg-mjcg
https://github.com/kylebrowning/APNSwift/security/advisories/GHSA-qh2w-vjxg-mjcg
https://github.com/kylebrowning/APNSwift/commit/97fa7f69dcdd89168fff84e0ba8f999881ee3d3f
https://github.com/kylebrowning/APNSwift/commit/97fa7f69dcdd89168fff84e0ba8f999881ee3d3f
https://github.com/kylebrowning/APNSwift/issues/31
https://github.com/kylebrowning/APNSwift/issues/31
https://github.com/kylebrowning/APNSwift/pull/32
https://github.com/kylebrowning/APNSwift/pull/32
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-4068