From f8c59e28af24621155c2ead26b758d6f96bf813d Mon Sep 17 00:00:00 2001 From: Thom Chiovoloni Date: Thu, 23 Apr 2020 10:21:55 -0700 Subject: [PATCH] Add advisory for rusqlite --- crates/rusqlite/RUSTSEC-0000-0000.toml | 25 +++++++++++++++++++++++++ 1 file changed, 25 insertions(+) create mode 100644 crates/rusqlite/RUSTSEC-0000-0000.toml diff --git a/crates/rusqlite/RUSTSEC-0000-0000.toml b/crates/rusqlite/RUSTSEC-0000-0000.toml new file mode 100644 index 0000000..b77b7ac --- /dev/null +++ b/crates/rusqlite/RUSTSEC-0000-0000.toml @@ -0,0 +1,25 @@ + +[advisory] +id = "RUSTSEC-0000-0000" +package = "rusqlite" +date = "2020-04-23" +title = "Various memory safety issues" +url = "https://github.com/rusqlite/rusqlite/releases/tag/0.23.0" + +description = """ +Several memory safety issues have been uncovered in an audit of +rusqlite. + +See https://github.com/rusqlite/rusqlite/releases/tag/0.23.0 for a complete list. +""" + +[affected.functions] +"rusqlite::trace::log" = ["< 0.23.0"] +"rusqlite::Connection::set_aux" = ["< 0.23.0"] +"rusqlite::Connection::get_aux" = ["< 0.23.0"] +"rusqlite::vtab::create_module" = ["< 0.23.0"] +"rusqlite::session::Session::attach" = ["< 0.23.0"] +"rusqlite::session::Session::diff" = ["< 0.23.0"] + +[versions] +patched = [">= 0.23.0"]