From a6c90b9cd0246a19e9e073ad47bf5f5c6dcb9fc1 Mon Sep 17 00:00:00 2001 From: Brian Smith Date: Wed, 30 Aug 2023 15:01:29 -0700 Subject: [PATCH] Update webpki RUSTSEC-2023-0052 advisory. (#1762) * Indicate release version that the fix landed in. * Remove unnecessary noise from the text. --- crates/webpki/RUSTSEC-2023-0052.md | 5 +---- 1 file changed, 1 insertion(+), 4 deletions(-) diff --git a/crates/webpki/RUSTSEC-2023-0052.md b/crates/webpki/RUSTSEC-2023-0052.md index 185c5f4..4d373c8 100644 --- a/crates/webpki/RUSTSEC-2023-0052.md +++ b/crates/webpki/RUSTSEC-2023-0052.md @@ -10,7 +10,7 @@ related = ["CVE-2018-16875"] aliases = ["GHSA-8qv2-5vq6-g2g7"] [versions] -patched = [] +patched = [">= 0.22.1"] ``` # webpki: CPU denial of service in certificate path building @@ -24,6 +24,3 @@ Both TLS clients and TLS servers that accept client certificate are affected. This was previously reported in and re-reported recently by Luke Malinowski. - -`rustls-webpki` is a fork of this crate which contains a fix for this issue -and is actively maintained.