[portaudio] add build script RCE

This commit is contained in:
Jake McGinty
2019-06-06 16:54:16 +09:00
parent 561a9d6e5b
commit 56350b2803

View File

@@ -0,0 +1,15 @@
[advisory]
id = "RUSTSEC-0000-0000"
package = "portaudio"
date = "2016-08-01"
title = "HTTP download and execution allows MitM RCE"
description = """
The build script in the portaudio crate will attempt to download via HTTP
the portaudio source and build it.
A Mallory in the middle can intercept the download with their own archive
and get RCE.
"""
patched_versions = []
url = "https://github.com/RustAudio/rust-portaudio/issues/144"
keywords = ["ssl", "mitm"]