From a1076cfa18e31a016c396610e8cb7343c2595c55 Mon Sep 17 00:00:00 2001 From: Ammar Askar Date: Sat, 26 Sep 2020 00:49:15 -0700 Subject: [PATCH] Add advisory for out-of-bounds read in array-queue. --- crates/array-queue/RUSTSEC-0000-0000.toml | 16 ++++++++++++++++ 1 file changed, 16 insertions(+) create mode 100644 crates/array-queue/RUSTSEC-0000-0000.toml diff --git a/crates/array-queue/RUSTSEC-0000-0000.toml b/crates/array-queue/RUSTSEC-0000-0000.toml new file mode 100644 index 0000000..6b00f78 --- /dev/null +++ b/crates/array-queue/RUSTSEC-0000-0000.toml @@ -0,0 +1,16 @@ +[advisory] +id = "RUSTSEC-0000-0000" +package = "array-queue" +date = "2020-09-26" +title = "array_queue pop_back allows an out-of-bounds read." +url = "https://github.com/raviqqe/array-queue/issues/2" +description = """ +array_queue implements a circular queue that wraps around an array. However, it +fails to properly index into the array in the `pop_back` function allowing the +reading of previously dropped or uninitialized memory. +""" +keywords = ["memory-corruption", "uninitialized-memory"] + + +[versions] +patched = []