From dc704601c0abf8ae99b973e485ec2143313be233 Mon Sep 17 00:00:00 2001 From: Alex Gaynor Date: Mon, 10 Dec 2018 19:48:20 -0500 Subject: [PATCH] Request RUSTSEC for resolved UAF in OpenSSL --- crates/openssl/RUSTSEC-0000-0000.toml | 20 ++++++++++++++++++++ 1 file changed, 20 insertions(+) create mode 100644 crates/openssl/RUSTSEC-0000-0000.toml diff --git a/crates/openssl/RUSTSEC-0000-0000.toml b/crates/openssl/RUSTSEC-0000-0000.toml new file mode 100644 index 0000000..96f3e1b --- /dev/null +++ b/crates/openssl/RUSTSEC-0000-0000.toml @@ -0,0 +1,20 @@ +[advisory] +id = "RUSTSEC-0000-0000" + +package = "openssl" + +date = "2018-06-01" + +title = "Use after free in CMS Signing" + +description = """ +Affected versions of the OpenSSL crate used structures after they'd been freed. +""" + +patched_versions = [">= 0.10.9"] + +unaffected_versions = ["< 0.10.8"] + +url = "https://github.com/sfackler/rust-openssl/pull/942" + +keywords = ["memory-corruption"]