Tony Arcieri
09936b6d4b
Merge pull request #119 from Shnatsel/patch-1
...
Add advisory for SmallVec issue #148
2019-07-02 15:21:43 -07:00
Sergey "Shnatsel" Davidoff
2cbddfd81d
Drop comments from new smallvec advisory
2019-07-02 22:55:15 +02:00
Sergey "Shnatsel" Davidoff
7af1eac5b1
Rename tentative advisory to please CI
2019-06-30 20:11:34 +02:00
Sergey "Shnatsel" Davidoff
144eb01eef
Add advisory for SmallVec issues #148
2019-06-30 20:04:20 +02:00
Tony Arcieri
7d2f62d5ed
Merge pull request #118 from RustSec/contributing/yanking
...
CONTRIBUTING.md: Recommend yanking affected versions (closes #74 )
2019-06-25 17:34:12 -07:00
Tony Arcieri
6890db2d53
CONTRIBUTING.md: Recommend yanking affected versions ( closes #74 )
...
This seems like the best advice we can give for now
2019-06-25 17:29:54 -07:00
Tony Arcieri
c49ac2cf3f
Merge pull request #117 from RustSec/RUSTSEC-2019-0008
...
Assign RUSTSEC-2019-0008 to simd-json
2019-06-24 13:31:19 -07:00
Tony Arcieri
f0a801979c
Assign RUSTSEC-2019-0008 to simd-json
...
Original PR: https://github.com/RustSec/advisory-db/pull/116
2019-06-24 13:20:43 -07:00
Tony Arcieri
003d42c27e
Merge pull request #116 from Licenser/simd-json-pr-27
...
Add advisory for segfault bug in simd-json.rs
2019-06-24 13:11:21 -07:00
Heinz N. Gies
8134840ade
Remove comments and fix spelling
2019-06-24 21:11:55 +02:00
Heinz N. Gies
f65960fb51
Add advisory for segfault bug in simd-json.rs
2019-06-24 21:11:55 +02:00
Tony Arcieri
fd759b72f2
Merge pull request #115 from RustSec/RUSTSEC-2019-0007
...
Assign RUSTSEC-2019-0007 to asn1_der
2019-06-24 10:20:14 -07:00
Tony Arcieri
602f9252e1
Assign RUSTSEC-2019-0007 to asn1_der
...
Original PR: https://github.com/RustSec/advisory-db/pull/113
2019-06-24 09:48:05 -07:00
Tony Arcieri
c1a4315346
Merge pull request #113 from KizzyCode/master
...
Filing issue for `asn1_der`
2019-06-24 09:46:17 -07:00
Tony Arcieri
67edcf34e4
Merge branch 'master' into master
2019-06-24 09:32:01 -07:00
Tony Arcieri
4d8795f676
Merge pull request #114 from 8573/8573/use-more-informative-wording-from-RS-2019-0005-in-RS-2019-0006/1
...
RUSTSEC-2019-0006: Use -0005's format vuln wording
2019-06-24 09:31:29 -07:00
c74d
63fbe9df35
RUSTSEC-2019-0006: Use -0005's format vuln wording
...
As filed, advisory RUSTSEC-2019-0006 simply notes that certain
functions in the covered crate create a "format vulnerability". This
patch, following up on [an exchange of comments on GitHub][1], edits
advisory RUSTSEC-2019-0006 to summarize the risk introduced by a
format vulnerability, copying the wording of the associated advisory
RUSTSEC-2019-0005.
[1]: <https://github.com/RustSec/advisory-db/pull/107#pullrequestreview-250212575 >
2019-06-23 00:41:31 +00:00
KizzyCode
2bc9806042
Removed comments
2019-06-22 00:17:25 +02:00
KizzyCode
6117c44711
Removed erroneous unaffected versions
2019-06-22 00:05:04 +02:00
KizzyCode
90d22af332
Create RUSTSEC-0000-0000.toml
...
Added vulnerability TOML for https://github.com/KizzyCode/asn1_der/issues/1
2019-06-21 23:54:40 +02:00
Tony Arcieri
4d3480cc76
Merge pull request #110 from RustSec/RUSTSEC-2019-0006
...
Reassign ncurses vuln from RUSTSEC-2019-0004 => 0006
2019-06-18 10:10:50 -07:00
Tony Arcieri
047a068ba7
Reassign ncurses vuln from RUSTSEC-2019-0004 => 0006
...
RUSTSEC-2019-0004 is already assigned to a `libp2p-core` vulnerability.
Apparently we don't have tests to catch this? Unfortunate.
2019-06-18 09:51:54 -07:00
Tony Arcieri
007d291379
Merge pull request #109 from RustSec/RUSTSEC-2019-0004+0005
...
Assign RUSTSEC-2019-0004 to ncurses; -0005 to pancurses
2019-06-18 09:45:56 -07:00
Tony Arcieri
c4397fd8dc
Assign RUSTSEC-2019-0005 to pancurses
...
Original PR: https://github.com/RustSec/advisory-db/pull/108
2019-06-18 09:28:49 -07:00
Tony Arcieri
759a11fa8c
Assign RUSTSEC-2019-0004 to ncurses
...
Original PR: https://github.com/RustSec/advisory-db/pull/107
2019-06-18 09:27:56 -07:00
Tony Arcieri
af0882d810
Merge pull request #107 from thomcc/curses-funcs
...
Add advisory for ncurses
2019-06-18 09:22:43 -07:00
Tony Arcieri
5522c6c9b9
Merge branch 'master' into curses-funcs
2019-06-18 09:13:44 -07:00
Tony Arcieri
66d2b7a148
Merge pull request #108 from thomcc/pancurses-mvprintw
...
Add advisory for pancurses
2019-06-18 09:12:54 -07:00
Thom Chiovoloni
7e9fe78ade
Add advisory for pancurses
2019-06-15 13:15:48 -07:00
Thom Chiovoloni
5466d5badf
Add advisory for ncurses
2019-06-15 13:14:05 -07:00
Tony Arcieri
733c7140d1
Merge pull request #105 from RustSec/RUSTSEC-2016-0003
...
Assign RUSTSEC-2016-0003 to portaudio
2019-06-06 17:42:30 -07:00
Tony Arcieri
300f36a20d
Assign RUSTSEC-2016-0003 to portaudio
...
Original PR: https://github.com/RustSec/advisory-db/pull/104
2019-06-06 17:34:55 -07:00
Tony Arcieri
d1911ab5ab
Merge pull request #104 from mcginty/master
...
[portaudio] add build script RCE
2019-06-06 17:31:58 -07:00
Jake McGinty
56350b2803
[portaudio] add build script RCE
2019-06-06 16:56:12 +09:00
Tony Arcieri
561a9d6e5b
Merge pull request #102 from ordian/master
...
[protobuf] fix patched versions
2019-05-20 06:51:53 -07:00
Andronik Ordian
49bae94718
[protobuf] fix patched versions
2019-05-20 15:45:47 +02:00
Tony Arcieri
76e9c2b32a
Merge pull request #103 from ordian/fix-libp2p
...
[libp2p-core] fix patched versions
2019-05-20 06:40:19 -07:00
Andronik Ordian
4b36267927
[libp2p-core] fix patched versions
2019-05-20 11:38:22 +02:00
Tony Arcieri
e4f5f2a627
Merge pull request #101 from RustSec/RUSTSEC-2019-0003/fix-date
...
RUSTSEC-2019-0003: Fix date
2019-05-19 17:05:10 -07:00
Tony Arcieri
c300327fd6
RUSTSEC-2019-0003: Fix date
...
Mistakenly logged as 2018
2019-05-19 16:51:18 -07:00
Tony Arcieri
39300b6c6d
Merge pull request #100 from oherrala/rustsec-2019-0003
...
protobuf 2.6.0 and 1.7.5 released with fix to RUSTSEC-2019-0003
2019-05-19 16:50:56 -07:00
Ossi Herrala
bfc6f36d20
protobuf 2.6.0 and 1.7.5 released with fix to this issue
2019-05-20 01:29:27 +03:00
Tony Arcieri
0854d2baee
Merge pull request #99 from RustSec/RUSTSEC-2019-0003+0004
...
Assign RUSTSEC-2019-0003 to protobuf; -0004 to libp2p-core
2019-05-15 14:01:40 -07:00
Tony Arcieri
58a4d5b2a2
Assign RUSTSEC-2019-0004 to libp2p-core
2019-05-15 13:41:19 -07:00
Tony Arcieri
ec1cf8ffb1
Assign RUSTSEC-2019-0003 to protobuf
2019-05-15 13:40:57 -07:00
Tony Arcieri
c1da669027
Merge pull request #98 from tomaka/libp2p-oops
...
Add libp2p ed25519 signature verification failure
2019-05-15 13:12:52 -07:00
Pierre Krieger
924dd24c23
Add libp2p ed25519 signature verification failure
2019-05-15 21:31:10 +02:00
Tony Arcieri
c6e83777b7
Merge pull request #97 from gedigi/master
...
Add protobuf out-of-memory vulnerability
2019-05-15 10:09:28 -07:00
Gerardo Di Giacomo
1a8bf5bc41
fixed key name
2019-05-15 09:30:53 -07:00
Gerardo Di Giacomo
f97b9a0ad3
Update RUSTSEC-0000-0000.toml
2019-05-14 19:44:00 -07:00