Commit Graph

786 Commits

Author SHA1 Message Date
github-actions[bot]
64d1651ee7 Assigned RUSTSEC-2020-0044 to atom 2020-09-26 16:04:29 +00:00
Sergey "Shnatsel" Davidoff
94949cbee4 Merge pull request #390 from ammaraskar/atom_issue
Add advisory for atom crate
2020-09-26 18:03:55 +02:00
Sergey "Shnatsel" Davidoff
ebd9ffcac8 Update RUSTSEC-0000-0000.toml 2020-09-26 12:27:30 +02:00
Sergey "Shnatsel" Davidoff
bd394d56fd Update RUSTSEC-0000-0000.toml 2020-09-26 12:26:17 +02:00
Sergey "Shnatsel" Davidoff
d0bdfc9546 Update RUSTSEC-0000-0000.toml 2020-09-26 12:25:05 +02:00
Sergey "Shnatsel" Davidoff
ee8f668400 Update RUSTSEC-0000-0000.toml 2020-09-26 12:23:43 +02:00
Ammar Askar
a1076cfa18 Add advisory for out-of-bounds read in array-queue. 2020-09-26 00:54:49 -07:00
Sergey "Shnatsel" Davidoff
92e5c88a73 Merge pull request #395 from RustSec/assign-ids
Assigned RUSTSEC-2020-0043 to ws
2020-09-25 16:09:22 +02:00
github-actions[bot]
687f999343 Assigned RUSTSEC-2020-0043 to ws 2020-09-25 12:55:36 +00:00
Sergey "Shnatsel" Davidoff
f63849d6b0 Merge pull request #394 from gnunicorn/ben-ws-rs
Insufficient size checks in outgoing buffer in `ws` allows remote attacker to run the process out of memory
2020-09-25 14:54:50 +02:00
Benjamin Kampmann
5a25462b61 the year is 2020 2020-09-25 12:23:05 +02:00
Benjamin Kampmann
61a2e15704 adding ws-rs advisory 2020-09-25 12:14:34 +02:00
Sergey "Shnatsel" Davidoff
2f05940af6 Merge pull request #393 from RustSec/assign-ids
Assigned RUSTSEC-2020-0042 to stack
2020-09-24 20:02:35 +02:00
github-actions[bot]
57fc37a584 Assigned RUSTSEC-2020-0042 to stack 2020-09-24 18:01:53 +00:00
Sergey "Shnatsel" Davidoff
be9ff03e38 Merge pull request #392 from ammaraskar/0016-stack
Add advisory for out-of-bounds write in stack crate
2020-09-24 20:01:13 +02:00
Ammar Askar
0fdd4d8a5c Add patched version 2020-09-24 10:33:22 -07:00
Ammar Askar
4c2d1c0d1b Add advisory for out-of-bounds write in stack crate 2020-09-24 03:03:13 -07:00
Alexander Kjäll
12198c5751 added CVE number (#387)
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25016
2020-09-23 07:52:00 -07:00
Alexander Kjäll
903e6532e6 added CVE numbers (#386)
looks like some confusion if the CVE is about this or RUSTSEC-2020-0036, but it looks like this is the actual security hole

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25575
2020-09-23 07:51:49 -07:00
Ammar Askar
f324f2d97c Add advisory for atom crate 2020-09-21 11:54:43 -07:00
Sergey "Shnatsel" Davidoff
d416cf5d86 Merge pull request #389 from alexanderkjall/patch-4
added CVE numbers
2020-09-20 12:30:35 +02:00
Alexander Kjäll
2be9a1531e added CVE numbers
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25791
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25792
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25793
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25794
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25795
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25796
2020-09-20 12:20:15 +02:00
Sergey "Shnatsel" Davidoff
69c1f45479 Merge pull request #388 from alexanderkjall/patch-3
added CVE number
2020-09-19 17:32:48 +02:00
Alexander Kjäll
e692f8f02f added CVE number
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25573
2020-09-19 17:23:47 +02:00
Alexander Kjäll
a14637fe62 added CVE number CVE-2020-25574 (#385)
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25574
2020-09-19 11:03:04 -04:00
Alexander Kjäll
ad7cf2f303 Added CVE number (#384)
http://cve.mitre.org/cgi-bin/cvename.cgi?name=2020-25576
2020-09-19 09:59:34 -04:00
Sergey "Shnatsel" Davidoff
49dba073a8 Merge pull request #382 from RustSec/assign-ids
Assigned RUSTSEC-2020-0041 to sized-chunks
2020-09-07 00:16:47 +02:00
github-actions[bot]
b5df32b9e6 Assigned RUSTSEC-2020-0041 to sized-chunks 2020-09-06 22:14:56 +00:00
Sergey "Shnatsel" Davidoff
e7e8aa347c Merge pull request #381 from Qwaz/0014-sized-chunks
sized-chunks: Multiple soundness issues in Chunk and InlineArray
2020-09-07 00:14:24 +02:00
Yechan Bae
5534479d2a Initial report for 0014-sized-chunks 2020-09-06 18:05:00 -04:00
Sergey "Shnatsel" Davidoff
88c518e88a Merge pull request #379 from Qwaz/0013-simple-slab-patched
Update patched version of 0013-simple-slab
2020-09-06 12:54:45 +02:00
Yechan Bae
3cd0280fe7 Update patched version of 0013-simple-slab 2020-09-06 04:26:47 -04:00
Sergey "Shnatsel" Davidoff
e44d93d9c6 Merge pull request #378 from RustSec/assign-ids
Assigned RUSTSEC-2020-0040 to obstack
2020-09-04 21:36:04 +02:00
github-actions[bot]
60caffb2bf Assigned RUSTSEC-2020-0040 to obstack 2020-09-04 19:35:03 +00:00
Sergey "Shnatsel" Davidoff
ec4382d316 Merge pull request #373 from Qwaz/0011-obstack
obstack: Obstack generates unaligned references
2020-09-04 21:34:28 +02:00
Sergey "Shnatsel" Davidoff
87aae01a36 mark ">= 0.1.4" as fixed 2020-09-04 21:32:48 +02:00
Sergey "Shnatsel" Davidoff
f5e8a8ef29 Merge pull request #377 from RustSec/assign-ids
Assigned RUSTSEC-2020-0039 to simple-slab
2020-09-04 12:11:34 +02:00
github-actions[bot]
d7fd255bf0 Assigned RUSTSEC-2020-0039 to simple-slab 2020-09-04 10:10:44 +00:00
Sergey "Shnatsel" Davidoff
4947069dc8 Merge pull request #376 from Qwaz/0013-simple-slab
simple-slab: `index()` allows out-of-bound read and `remove()` has off-by-one error
2020-09-04 12:10:07 +02:00
Yechan Bae
d2aaa6c1b2 Initial report for 0013-simple-slab 2020-09-03 23:56:02 -04:00
Sergey "Shnatsel" Davidoff
95868762d3 Merge pull request #375 from RustSec/assign-ids
Assigned RUSTSEC-2020-0038 to ordnung
2020-09-03 13:22:01 +02:00
github-actions[bot]
75a29e606a Assigned RUSTSEC-2020-0038 to ordnung 2020-09-03 10:47:37 +00:00
Sergey "Shnatsel" Davidoff
0cee8f8f4d Merge pull request #374 from Qwaz/0012-ordnung
ordnung: Memory safety issues in `compact::Vec`
2020-09-03 12:47:00 +02:00
Yechan Bae
d5811c82b2 Update 0012-ordnung 2020-09-03 06:29:27 -04:00
Yechan Bae
daf2b6281a Initial report for 0011-obstack 2020-09-03 02:27:06 -04:00
Sergey "Shnatsel" Davidoff
68e0e1f7c0 Merge pull request #372 from RustSec/assign-ids
Assigned RUSTSEC-2020-0037 to crayon
2020-08-31 23:38:51 +02:00
github-actions[bot]
fe43002372 Assigned RUSTSEC-2020-0037 to crayon 2020-08-31 21:35:14 +00:00
Sergey "Shnatsel" Davidoff
8acfb6ad12 Merge pull request #371 from Qwaz/0010-crayon
crayon: Misbehaving `HandleLike` implementation can lead to memory safety violation
2020-08-31 23:34:37 +02:00
Yechan Bae
484d002213 Initial report for 0010-crayon 2020-08-31 17:14:55 -04:00
Sergey "Shnatsel" Davidoff
c341943a3c Merge pull request #352 from RustSec/lz-fear-suggestion
Suggest lz-fear as an alternative to lz4-compress
2020-08-27 22:59:48 +02:00