Merge pull request #192 from kpp/master

PartialEq implementation for sodiumoxide::crypto::generichash::Digest has compared itself to itself
This commit is contained in:
Tony Arcieri
2019-10-11 11:42:13 -07:00
committed by GitHub

View File

@@ -0,0 +1,18 @@
[advisory]
id = "RUSTSEC-0000-0000"
package = "sodiumoxide"
date = "2019-10-11"
url = "https://github.com/sodiumoxide/sodiumoxide/pull/381"
title = "generichash::Digest::eq always return true"
description = """
PartialEq implementation for generichash::Digest has compared itself to itself.
Digest::eq always returns true and Digest::ne always returns false.
"""
patched_versions = [">= 0.2.5"]
keywords = ["cryptography"]
[affected.functions]
"sodiumoxide::crypto::generichash::Digest::eq" = ["< 0.2.5, >= 0.1.0"]
"sodiumoxide::crypto::generichash::Digest::ne" = ["< 0.2.5, >= 0.1.0"]