From 9a81b244aae6df636adcaa1b113e605fd0b7e8f2 Mon Sep 17 00:00:00 2001 From: Jon Moroney Date: Thu, 9 Sep 2021 14:48:07 -0700 Subject: [PATCH] Add rustsec advisory for GHSA-82hm-vh7g-hrh9 (#1021) --- crates/molecule/RUSTSEC-0000-0000.md | 13 +++++++++++++ 1 file changed, 13 insertions(+) create mode 100644 crates/molecule/RUSTSEC-0000-0000.md diff --git a/crates/molecule/RUSTSEC-0000-0000.md b/crates/molecule/RUSTSEC-0000-0000.md new file mode 100644 index 0000000..4b7cce7 --- /dev/null +++ b/crates/molecule/RUSTSEC-0000-0000.md @@ -0,0 +1,13 @@ +```toml +[advisory] +id = "RUSTSEC-0000-0000" +package = "molecule" +date = "2021-07-30" +url = "https://github.com/nervosnetwork/molecule/security/advisories/GHSA-82hm-vh7g-hrh9" +[versions] +patched = [">= 0.7.2"] +``` + +# Partial read is incorrect in molecule + +Anyone who uses total_size(..) function to partial read the length of any FixVec will get an incorrect result, due to an incorrect implementation. This has been resolved in the 0.7.2 release.