diff --git a/crates/openssl/RUSTSEC-0000-0000.toml b/crates/openssl/RUSTSEC-0000-0000.toml new file mode 100644 index 0000000..96f3e1b --- /dev/null +++ b/crates/openssl/RUSTSEC-0000-0000.toml @@ -0,0 +1,20 @@ +[advisory] +id = "RUSTSEC-0000-0000" + +package = "openssl" + +date = "2018-06-01" + +title = "Use after free in CMS Signing" + +description = """ +Affected versions of the OpenSSL crate used structures after they'd been freed. +""" + +patched_versions = [">= 0.10.9"] + +unaffected_versions = ["< 0.10.8"] + +url = "https://github.com/sfackler/rust-openssl/pull/942" + +keywords = ["memory-corruption"]