Commit Graph

721 Commits

Author SHA1 Message Date
github-actions[bot]
b136b74460 Assigned RUSTSEC-2020-0051 to rustsec (#416)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2020-10-01 08:21:08 -07:00
Tony Arcieri
bfa9e12685 Add rustsec crate advisory for breaking changes to advisory format (#415)
In theory this advisory should trigger this feature of `cargo-audit`
which checks for advisories filed against the `rustsec` crate:

https://github.com/RustSec/cargo-audit/blob/783f221/src/auditor.rs#L178-L199

After merging, I will test with an older `cargo-audit` version to see if
it has the intended effect.
2020-10-01 08:19:41 -07:00
Sergey "Shnatsel" Davidoff
707e364a4a Merge pull request #412 from RustSec/assign-ids
Assigned RUSTSEC-2020-0050 to dync
2020-09-27 21:10:40 +02:00
github-actions[bot]
a1f39cc8c9 Assigned RUSTSEC-2020-0050 to dync 2020-09-27 19:10:29 +00:00
Sergey "Shnatsel" Davidoff
b5a4582a26 Merge pull request #411 from ammaraskar/0018-dync
Add misaligned-access soundness issue for dync crate
2020-09-27 21:09:51 +02:00
Ammar Askar
7f5deb94c0 Add misaligned-access soundness issue for dync crate 2020-09-27 11:59:16 -07:00
Sergey "Shnatsel" Davidoff
cdbb09428a Merge pull request #410 from RustSec/assign-ids
Assigned RUSTSEC-2018-0019 to actix-web
2020-09-26 22:38:22 +02:00
github-actions[bot]
fe2503798e Assigned RUSTSEC-2018-0019 to actix-web 2020-09-26 20:38:10 +00:00
Sergey "Shnatsel" Davidoff
c6d6a43c6d Merge pull request #409 from RustSec/old-actix
Add advisory for very old, unsound actix-web
2020-09-26 22:37:35 +02:00
Sergey "Shnatsel" Davidoff
2522178d5b Add advisory for very old, unsound Actix 2020-09-26 22:12:12 +02:00
Sergey "Shnatsel" Davidoff
2c3b462fbb Merge pull request #408 from RustSec/assign-ids
Assigned RUSTSEC-2020-0049 to actix-codec
2020-09-26 21:52:05 +02:00
github-actions[bot]
cc3f69c160 Assigned RUSTSEC-2020-0049 to actix-codec 2020-09-26 19:51:53 +00:00
Sergey "Shnatsel" Davidoff
0ef27ed422 Merge pull request #407 from RustSec/actix-codec-pin
Advisory for unsound pinning in actix-codec
2020-09-26 21:51:21 +02:00
Sergey "Shnatsel" Davidoff
f4faaa9cc3 drop comment 2020-09-26 21:49:09 +02:00
Sergey "Shnatsel" Davidoff
74e8568389 Advisory for unsound pinning in actix-codec 2020-09-26 21:47:56 +02:00
Sergey "Shnatsel" Davidoff
17d2fd9b41 fix date for real this time 2020-09-26 21:32:13 +02:00
Sergey "Shnatsel" Davidoff
4b4a41e7c5 Merge pull request #406 from RustSec/RUSTSEC-2020-0048
Assign RUSTSEC-2020-0048 to actix-http
2020-09-26 21:31:24 +02:00
Sergey "Shnatsel" Davidoff
25c3aaaf6c Assign RUSTSEC-2020-0048 to actix-http 2020-09-26 21:31:13 +02:00
Sergey "Shnatsel" Davidoff
14f4dbb09a fix date more 2020-09-26 21:29:49 +02:00
Sergey "Shnatsel" Davidoff
8974b0f390 Merge pull request #402 from RustSec/actix-http-pin
Advisory for unsound pinning in actix-http
2020-09-26 21:22:39 +02:00
Sergey "Shnatsel" Davidoff
09a306dbc2 fix date 2020-09-26 21:17:03 +02:00
Sergey "Shnatsel" Davidoff
dfed968bcc Merge pull request #403 from RustSec/assign-ids
Assigned RUSTSEC-2020-0047 to array-queue
2020-09-26 19:59:59 +02:00
github-actions[bot]
b091551faf Assigned RUSTSEC-2020-0047 to array-queue 2020-09-26 17:46:05 +00:00
Sergey "Shnatsel" Davidoff
9b360973e2 Merge pull request #396 from ammaraskar/0017-array-queue
Add advisory for out-of-bounds read in array-queue.
2020-09-26 19:45:28 +02:00
Sergey "Shnatsel" Davidoff
6f59b11780 Advisory for unsound pinning in actix-http 2020-09-26 19:35:10 +02:00
Sergey "Shnatsel" Davidoff
ad014c6034 Merge pull request #401 from RustSec/assign-ids
Assigned RUSTSEC-2020-0046 to actix-service
2020-09-26 19:07:26 +02:00
github-actions[bot]
9fe2230dcc Assigned RUSTSEC-2020-0046 to actix-service 2020-09-26 17:07:03 +00:00
Sergey "Shnatsel" Davidoff
db20f9b701 Merge pull request #399 from RustSec/actix-service-cell
Add advisory for unsound Cell in actix-service
2020-09-26 19:06:04 +02:00
Sergey "Shnatsel" Davidoff
94c5614c01 Merge pull request #400 from RustSec/assign-ids
Assigned RUSTSEC-2020-0045 to actix-utils
2020-09-26 19:05:39 +02:00
github-actions[bot]
0eb24bf2a5 Assigned RUSTSEC-2020-0045 to actix-utils 2020-09-26 17:05:26 +00:00
Sergey "Shnatsel" Davidoff
683896fdc5 Merge pull request #398 from RustSec/actix-utils-cell
add advisory for custom Cell in actix-utils
2020-09-26 19:04:49 +02:00
Sergey "Shnatsel" Davidoff
90ac1e0dea Add advisory for unsound Cell in actix-service 2020-09-26 18:43:20 +02:00
Sergey "Shnatsel" Davidoff
41f95e41cb fix url 2020-09-26 18:37:46 +02:00
Sergey "Shnatsel" Davidoff
f7c02faed1 add advisory for custom Cell in actix-utils 2020-09-26 18:31:04 +02:00
Sergey "Shnatsel" Davidoff
b8a3072607 Merge pull request #397 from RustSec/assign-ids
Assigned RUSTSEC-2020-0044 to atom
2020-09-26 18:06:21 +02:00
github-actions[bot]
64d1651ee7 Assigned RUSTSEC-2020-0044 to atom 2020-09-26 16:04:29 +00:00
Sergey "Shnatsel" Davidoff
94949cbee4 Merge pull request #390 from ammaraskar/atom_issue
Add advisory for atom crate
2020-09-26 18:03:55 +02:00
Sergey "Shnatsel" Davidoff
ebd9ffcac8 Update RUSTSEC-0000-0000.toml 2020-09-26 12:27:30 +02:00
Sergey "Shnatsel" Davidoff
bd394d56fd Update RUSTSEC-0000-0000.toml 2020-09-26 12:26:17 +02:00
Sergey "Shnatsel" Davidoff
d0bdfc9546 Update RUSTSEC-0000-0000.toml 2020-09-26 12:25:05 +02:00
Sergey "Shnatsel" Davidoff
ee8f668400 Update RUSTSEC-0000-0000.toml 2020-09-26 12:23:43 +02:00
Ammar Askar
a1076cfa18 Add advisory for out-of-bounds read in array-queue. 2020-09-26 00:54:49 -07:00
Sergey "Shnatsel" Davidoff
92e5c88a73 Merge pull request #395 from RustSec/assign-ids
Assigned RUSTSEC-2020-0043 to ws
2020-09-25 16:09:22 +02:00
github-actions[bot]
687f999343 Assigned RUSTSEC-2020-0043 to ws 2020-09-25 12:55:36 +00:00
Sergey "Shnatsel" Davidoff
f63849d6b0 Merge pull request #394 from gnunicorn/ben-ws-rs
Insufficient size checks in outgoing buffer in `ws` allows remote attacker to run the process out of memory
2020-09-25 14:54:50 +02:00
Benjamin Kampmann
5a25462b61 the year is 2020 2020-09-25 12:23:05 +02:00
Benjamin Kampmann
61a2e15704 adding ws-rs advisory 2020-09-25 12:14:34 +02:00
Sergey "Shnatsel" Davidoff
2f05940af6 Merge pull request #393 from RustSec/assign-ids
Assigned RUSTSEC-2020-0042 to stack
2020-09-24 20:02:35 +02:00
github-actions[bot]
57fc37a584 Assigned RUSTSEC-2020-0042 to stack 2020-09-24 18:01:53 +00:00
Sergey "Shnatsel" Davidoff
be9ff03e38 Merge pull request #392 from ammaraskar/0016-stack
Add advisory for out-of-bounds write in stack crate
2020-09-24 20:01:13 +02:00