Merge pull request #267 from thomcc/rusqlite

Add advisory for rusqlite
This commit is contained in:
Tony Arcieri
2020-04-24 12:39:27 -07:00
committed by GitHub

View File

@@ -0,0 +1,25 @@
[advisory]
id = "RUSTSEC-0000-0000"
package = "rusqlite"
date = "2020-04-23"
title = "Various memory safety issues"
url = "https://github.com/rusqlite/rusqlite/releases/tag/0.23.0"
description = """
Several memory safety issues have been uncovered in an audit of
rusqlite.
See https://github.com/rusqlite/rusqlite/releases/tag/0.23.0 for a complete list.
"""
[affected.functions]
"rusqlite::trace::log" = ["< 0.23.0"]
"rusqlite::Connection::set_aux" = ["< 0.23.0"]
"rusqlite::Connection::get_aux" = ["< 0.23.0"]
"rusqlite::vtab::create_module" = ["< 0.23.0"]
"rusqlite::session::Session::attach" = ["< 0.23.0"]
"rusqlite::session::Session::diff" = ["< 0.23.0"]
[versions]
patched = [">= 0.23.0"]