Commit Graph

704 Commits

Author SHA1 Message Date
Sergey "Shnatsel" Davidoff
25c3aaaf6c Assign RUSTSEC-2020-0048 to actix-http 2020-09-26 21:31:13 +02:00
Sergey "Shnatsel" Davidoff
14f4dbb09a fix date more 2020-09-26 21:29:49 +02:00
Sergey "Shnatsel" Davidoff
8974b0f390 Merge pull request #402 from RustSec/actix-http-pin
Advisory for unsound pinning in actix-http
2020-09-26 21:22:39 +02:00
Sergey "Shnatsel" Davidoff
09a306dbc2 fix date 2020-09-26 21:17:03 +02:00
Sergey "Shnatsel" Davidoff
dfed968bcc Merge pull request #403 from RustSec/assign-ids
Assigned RUSTSEC-2020-0047 to array-queue
2020-09-26 19:59:59 +02:00
github-actions[bot]
b091551faf Assigned RUSTSEC-2020-0047 to array-queue 2020-09-26 17:46:05 +00:00
Sergey "Shnatsel" Davidoff
9b360973e2 Merge pull request #396 from ammaraskar/0017-array-queue
Add advisory for out-of-bounds read in array-queue.
2020-09-26 19:45:28 +02:00
Sergey "Shnatsel" Davidoff
6f59b11780 Advisory for unsound pinning in actix-http 2020-09-26 19:35:10 +02:00
Sergey "Shnatsel" Davidoff
ad014c6034 Merge pull request #401 from RustSec/assign-ids
Assigned RUSTSEC-2020-0046 to actix-service
2020-09-26 19:07:26 +02:00
github-actions[bot]
9fe2230dcc Assigned RUSTSEC-2020-0046 to actix-service 2020-09-26 17:07:03 +00:00
Sergey "Shnatsel" Davidoff
db20f9b701 Merge pull request #399 from RustSec/actix-service-cell
Add advisory for unsound Cell in actix-service
2020-09-26 19:06:04 +02:00
Sergey "Shnatsel" Davidoff
94c5614c01 Merge pull request #400 from RustSec/assign-ids
Assigned RUSTSEC-2020-0045 to actix-utils
2020-09-26 19:05:39 +02:00
github-actions[bot]
0eb24bf2a5 Assigned RUSTSEC-2020-0045 to actix-utils 2020-09-26 17:05:26 +00:00
Sergey "Shnatsel" Davidoff
683896fdc5 Merge pull request #398 from RustSec/actix-utils-cell
add advisory for custom Cell in actix-utils
2020-09-26 19:04:49 +02:00
Sergey "Shnatsel" Davidoff
90ac1e0dea Add advisory for unsound Cell in actix-service 2020-09-26 18:43:20 +02:00
Sergey "Shnatsel" Davidoff
41f95e41cb fix url 2020-09-26 18:37:46 +02:00
Sergey "Shnatsel" Davidoff
f7c02faed1 add advisory for custom Cell in actix-utils 2020-09-26 18:31:04 +02:00
Sergey "Shnatsel" Davidoff
b8a3072607 Merge pull request #397 from RustSec/assign-ids
Assigned RUSTSEC-2020-0044 to atom
2020-09-26 18:06:21 +02:00
github-actions[bot]
64d1651ee7 Assigned RUSTSEC-2020-0044 to atom 2020-09-26 16:04:29 +00:00
Sergey "Shnatsel" Davidoff
94949cbee4 Merge pull request #390 from ammaraskar/atom_issue
Add advisory for atom crate
2020-09-26 18:03:55 +02:00
Sergey "Shnatsel" Davidoff
ebd9ffcac8 Update RUSTSEC-0000-0000.toml 2020-09-26 12:27:30 +02:00
Sergey "Shnatsel" Davidoff
bd394d56fd Update RUSTSEC-0000-0000.toml 2020-09-26 12:26:17 +02:00
Sergey "Shnatsel" Davidoff
d0bdfc9546 Update RUSTSEC-0000-0000.toml 2020-09-26 12:25:05 +02:00
Sergey "Shnatsel" Davidoff
ee8f668400 Update RUSTSEC-0000-0000.toml 2020-09-26 12:23:43 +02:00
Ammar Askar
a1076cfa18 Add advisory for out-of-bounds read in array-queue. 2020-09-26 00:54:49 -07:00
Sergey "Shnatsel" Davidoff
92e5c88a73 Merge pull request #395 from RustSec/assign-ids
Assigned RUSTSEC-2020-0043 to ws
2020-09-25 16:09:22 +02:00
github-actions[bot]
687f999343 Assigned RUSTSEC-2020-0043 to ws 2020-09-25 12:55:36 +00:00
Sergey "Shnatsel" Davidoff
f63849d6b0 Merge pull request #394 from gnunicorn/ben-ws-rs
Insufficient size checks in outgoing buffer in `ws` allows remote attacker to run the process out of memory
2020-09-25 14:54:50 +02:00
Benjamin Kampmann
5a25462b61 the year is 2020 2020-09-25 12:23:05 +02:00
Benjamin Kampmann
61a2e15704 adding ws-rs advisory 2020-09-25 12:14:34 +02:00
Sergey "Shnatsel" Davidoff
2f05940af6 Merge pull request #393 from RustSec/assign-ids
Assigned RUSTSEC-2020-0042 to stack
2020-09-24 20:02:35 +02:00
github-actions[bot]
57fc37a584 Assigned RUSTSEC-2020-0042 to stack 2020-09-24 18:01:53 +00:00
Sergey "Shnatsel" Davidoff
be9ff03e38 Merge pull request #392 from ammaraskar/0016-stack
Add advisory for out-of-bounds write in stack crate
2020-09-24 20:01:13 +02:00
Ammar Askar
0fdd4d8a5c Add patched version 2020-09-24 10:33:22 -07:00
Ammar Askar
4c2d1c0d1b Add advisory for out-of-bounds write in stack crate 2020-09-24 03:03:13 -07:00
Alexander Kjäll
12198c5751 added CVE number (#387)
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25016
2020-09-23 07:52:00 -07:00
Alexander Kjäll
903e6532e6 added CVE numbers (#386)
looks like some confusion if the CVE is about this or RUSTSEC-2020-0036, but it looks like this is the actual security hole

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25575
2020-09-23 07:51:49 -07:00
Ammar Askar
f324f2d97c Add advisory for atom crate 2020-09-21 11:54:43 -07:00
Sergey "Shnatsel" Davidoff
d416cf5d86 Merge pull request #389 from alexanderkjall/patch-4
added CVE numbers
2020-09-20 12:30:35 +02:00
Alexander Kjäll
2be9a1531e added CVE numbers
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25791
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25792
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25793
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25794
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25795
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25796
2020-09-20 12:20:15 +02:00
Sergey "Shnatsel" Davidoff
69c1f45479 Merge pull request #388 from alexanderkjall/patch-3
added CVE number
2020-09-19 17:32:48 +02:00
Alexander Kjäll
e692f8f02f added CVE number
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25573
2020-09-19 17:23:47 +02:00
Alexander Kjäll
a14637fe62 added CVE number CVE-2020-25574 (#385)
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25574
2020-09-19 11:03:04 -04:00
Alexander Kjäll
ad7cf2f303 Added CVE number (#384)
http://cve.mitre.org/cgi-bin/cvename.cgi?name=2020-25576
2020-09-19 09:59:34 -04:00
Sergey "Shnatsel" Davidoff
49dba073a8 Merge pull request #382 from RustSec/assign-ids
Assigned RUSTSEC-2020-0041 to sized-chunks
2020-09-07 00:16:47 +02:00
github-actions[bot]
b5df32b9e6 Assigned RUSTSEC-2020-0041 to sized-chunks 2020-09-06 22:14:56 +00:00
Sergey "Shnatsel" Davidoff
e7e8aa347c Merge pull request #381 from Qwaz/0014-sized-chunks
sized-chunks: Multiple soundness issues in Chunk and InlineArray
2020-09-07 00:14:24 +02:00
Yechan Bae
5534479d2a Initial report for 0014-sized-chunks 2020-09-06 18:05:00 -04:00
Sergey "Shnatsel" Davidoff
88c518e88a Merge pull request #379 from Qwaz/0013-simple-slab-patched
Update patched version of 0013-simple-slab
2020-09-06 12:54:45 +02:00
Yechan Bae
3cd0280fe7 Update patched version of 0013-simple-slab 2020-09-06 04:26:47 -04:00