Commit Graph

1489 Commits

Author SHA1 Message Date
Sergey "Shnatsel" Davidoff
b99d8a1347 Add GHSA alias to RUSTSEC-2021-0104 (#1038) 2021-09-10 16:01:55 +00:00
github-actions[bot]
8b677b0f9a Assigned RUSTSEC-2021-0109 to ckb (#1035)
Co-authored-by: Shnatsel <Shnatsel@users.noreply.github.com>
2021-09-10 15:58:38 +00:00
Sergey "Shnatsel" Davidoff
204c1ae2c6 add GHSA alias to RUSTSEC-2021-0101 (#1036) 2021-09-10 15:58:27 +00:00
Sergey "Shnatsel" Davidoff
a665da67eb Add GHSA alias to RUSTSEC-2021-0102 2021-09-10 15:58:05 +00:00
Jon Moroney
b838a4c68c Add rustsec advisory for GHSA-45p7-c959-rgcm (#1025)
* Add rustsec advisory for GHSA-45p7-c959-rgcm

* Update RUSTSEC-0000-0000.md

Co-authored-by: Sergey "Shnatsel" Davidoff <shnatsel@gmail.com>
2021-09-10 15:53:59 +00:00
github-actions[bot]
5046464393 Assigned RUSTSEC-2021-0108 to ckb (#1034)
Co-authored-by: Shnatsel <Shnatsel@users.noreply.github.com>
2021-09-10 15:52:06 +00:00
Jon Moroney
ef8532be92 Add rustsec advisory for GHSA-48vq-8jqv-gm6f (#1024)
* Add rustsec advisory for GHSA-48vq-8jqv-gm6f

* Update RUSTSEC-0000-0000.md

Co-authored-by: Sergey "Shnatsel" Davidoff <shnatsel@gmail.com>
2021-09-10 15:50:49 +00:00
github-actions[bot]
315a5c0609 Assigned RUSTSEC-2020-0157 to vm-memory, RUSTSEC-2021-0107 to ckb (#1033)
Co-authored-by: Shnatsel <Shnatsel@users.noreply.github.com>
2021-09-10 15:50:27 +00:00
Jon Moroney
f969fe8995 Add rustsec advisory for GHSA-mm4m-qg48-f7wc (#1018)
* Add rustsec advisory for GHSA-mm4m-qg48-f7wc

* Add GHSA to aliases

Co-authored-by: Sergey "Shnatsel" Davidoff <shnatsel@gmail.com>
2021-09-10 15:48:48 +00:00
Jon Moroney
181cf280e9 Add rustsec advisory for GHSA-v666-6w97-pcwm (#1015)
* Add rustsec advisory for GHSA-v666-6w97-pcwm

* Update RUSTSEC-0000-0000.md

Co-authored-by: Sergey "Shnatsel" Davidoff <shnatsel@gmail.com>
2021-09-10 15:47:22 +00:00
github-actions[bot]
ec858f80ef Assigned RUSTSEC-2021-0106 to bat (#1032)
Co-authored-by: alex <alex@users.noreply.github.com>
2021-09-09 18:41:38 -04:00
Jon Moroney
10fa105f05 Add rustsec advisory for GHSA-p24j-h477-76q3 (#1017)
* Add rustsec advisory for GHSA-p24j-h477-76q3

* Update crates/bat/RUSTSEC-0000-0000.md

Co-authored-by: Alex Gaynor <alex.gaynor@gmail.com>

* Update RUSTSEC-0000-0000.md

Capitalize `windows` to conform with https://docs.rs/platforms/1.1.0/platforms/target/enum.OS.html

* Update RUSTSEC-0000-0000.md

Add [affected] section

Co-authored-by: Alex Gaynor <alex.gaynor@gmail.com>
2021-09-09 18:40:15 -04:00
github-actions[bot]
fe4e45e52f Assigned RUSTSEC-2021-0105 to git-delta (#1031)
Co-authored-by: alex <alex@users.noreply.github.com>
2021-09-09 18:40:10 -04:00
Jon Moroney
fa5597ee92 Add rustsec advisory for GHSA-5xg3-j2j6-rcx4 (#1023)
* Add rustsec advisory for GHSA-5xg3-j2j6-rcx4

* Update RUSTSEC-0000-0000.md

Add [affected] section
2021-09-09 18:38:41 -04:00
github-actions[bot]
71f18afd3b Assigned RUSTSEC-2020-0156 to libsecp256k1-rs (#1030)
Co-authored-by: alex <alex@users.noreply.github.com>
2021-09-09 17:53:06 -04:00
Jon Moroney
e5b66bfe9e Add rustsec advisory for GHSA-7cqg-8449-rmfv (#1022) 2021-09-09 17:51:48 -04:00
github-actions[bot]
4b4a4d8d88 Assigned RUSTSEC-2021-0104 to pleaser (#1029)
Co-authored-by: alex <alex@users.noreply.github.com>
2021-09-09 17:51:08 -04:00
Jon Moroney
951070000d Add rustsec advisory for GHSA-f3fg-5j9p-vchc (#1020) 2021-09-09 17:49:39 -04:00
github-actions[bot]
8e5d566ef0 Assigned RUSTSEC-2021-0103 to molecule (#1028)
Co-authored-by: alex <alex@users.noreply.github.com>
2021-09-09 17:49:20 -04:00
Jon Moroney
9a81b244aa Add rustsec advisory for GHSA-82hm-vh7g-hrh9 (#1021) 2021-09-09 17:48:07 -04:00
github-actions[bot]
9dbe26271a Assigned RUSTSEC-2021-0102 to pleaser (#1027)
Co-authored-by: alex <alex@users.noreply.github.com>
2021-09-09 17:47:42 -04:00
Jon Moroney
841ecbf1b2 Add rustsec advisory for GHSA-pp74-39w2-v4w9 (#1016) 2021-09-09 17:45:16 -04:00
github-actions[bot]
b59e06ec22 Assigned RUSTSEC-2021-0101 to pleaser (#1026)
Co-authored-by: alex <alex@users.noreply.github.com>
2021-09-09 17:38:52 -04:00
Jon Moroney
27820b701d Add rustsec advisory for GHSA-vc5p-j8vw-mc6x (#1014) 2021-09-09 17:36:33 -04:00
github-actions[bot]
3e31699c08 Assigned RUSTSEC-2021-0100 to sha2 (#1013)
Co-authored-by: tarcieri <tarcieri@users.noreply.github.com>
2021-09-09 10:22:48 -06:00
Tony Arcieri
4744ee629e Add sha2 v0.9.7 AVX2 bug (#1012) 2021-09-09 10:14:52 -06:00
github-actions[bot]
138fb15795 Assigned RUSTSEC-2021-0099 to cosmos_sdk (#1011)
Co-authored-by: tarcieri <tarcieri@users.noreply.github.com>
2021-08-25 08:54:10 -06:00
Tony Arcieri
0f2bc2d6ee Add unmaintained crate advisory for cosmos_sdk (#1010)
It has been renamed to `cosmrs`:

https://github.com/cosmos/cosmos-rust/tree/main/cosmrs
2021-08-25 08:47:17 -06:00
github-actions[bot]
1be9534293 Assigned RUSTSEC-2021-0098 to openssl-src (#1009)
Co-authored-by: Shnatsel <Shnatsel@users.noreply.github.com>
2021-08-24 17:53:35 +02:00
Alexis Mousset
10b6f1e350 add cve-2021-3712 for openssl-src (#1007) 2021-08-24 17:52:03 +02:00
github-actions[bot]
ceea398762 Assigned RUSTSEC-2021-0097 to openssl-src (#1008)
Co-authored-by: tarcieri <tarcieri@users.noreply.github.com>
2021-08-24 09:37:57 -06:00
Alexis Mousset
100b12d997 add cve-2021-3711 for openssl-src (#1006) 2021-08-24 09:36:20 -06:00
github-actions[bot]
9f1d4c902c Assigned RUSTSEC-2021-0096 to spirv_headers (#1005)
Co-authored-by: tarcieri <tarcieri@users.noreply.github.com>
2021-08-23 08:34:15 -06:00
Jasper Bekkers
2f117ce3f1 spirv_headers is deprecated (#982)
* spirv_headers is deprecated

* Update crates/spirv_headers/RUSTSEC-0000-0000

Co-authored-by: Tony Arcieri <bascule@gmail.com>

* Rename RUSTSEC-0000-0000 to RUSTSEC-0000-0000.md

Co-authored-by: Tony Arcieri <bascule@gmail.com>
2021-08-23 08:17:39 -06:00
Marijn Suijten
d711272311 ash: RUSTSEC-2021-0090 has been patched in 0.33.1 (#1004)
https://github.com/MaikKlein/ash/issues/354 was fixed in https://github.com/MaikKlein/ash/pull/470.
2021-08-23 15:04:28 +03:00
Sergey "Shnatsel" Davidoff
45f9665f13 Fix CVE alias CVE-2020-35920 (#1003)
* drop wrong alias in net2 advisory

* add CVE-2020-35920 alias to the proper crate
2021-08-23 13:51:39 +03:00
Niklas Fiekas
101d914e04 RUSTSEC-2021-0089 has been patched in raw-cpuid 9.1.1 (#1002) 2021-08-22 12:43:52 +03:00
github-actions[bot]
b6a20c1ba3 Assigned RUSTSEC-2021-0095 to mopa (#1001)
Co-authored-by: tarcieri <tarcieri@users.noreply.github.com>
2021-08-21 19:48:14 -06:00
kotauskas
59cdbf2173 mopa is technically unsound (#927)
* Added the mopa vulnerability

* Update crates/mopa/RUSTSEC-0000-0000.md

Co-authored-by: Tony Arcieri <bascule@gmail.com>
2021-08-21 19:46:55 -06:00
github-actions[bot]
4b01805939 Assigned RUSTSEC-2021-0094 to rdiff (#1000)
Co-authored-by: tarcieri <tarcieri@users.noreply.github.com>
2021-08-21 19:46:40 -06:00
Ammar Askar
89842247a4 Add advisory for out-of-bounds read in rdiff (#862)
* Add advisory for out-of-bounds read in rdiff

* Update crates/rdiff/RUSTSEC-0000-0000.md

Co-authored-by: Tony Arcieri <bascule@gmail.com>
2021-08-21 19:44:58 -06:00
github-actions[bot]
14af874fad Assigned RUSTSEC-2021-0093 to crossbeam-deque (#999)
Co-authored-by: tarcieri <tarcieri@users.noreply.github.com>
2021-08-21 19:44:22 -06:00
Taiki Endo
670b28875f Add advisory for data race in crossbeam-deque (#970) 2021-08-21 19:43:00 -06:00
github-actions[bot]
8d3e99a38a Assigned RUSTSEC-2021-0092 to messagepack-rs (#998)
Co-authored-by: tarcieri <tarcieri@users.noreply.github.com>
2021-08-21 19:41:04 -06:00
Ammar Askar
460ac8be0d Add advisory for uninitialized exposure in messagepack-rs (#835) 2021-08-21 19:39:40 -06:00
github-actions[bot]
cf6f9d252e Assigned RUSTSEC-2021-0091 to gfx-auxil (#997)
Co-authored-by: tarcieri <tarcieri@users.noreply.github.com>
2021-08-21 19:39:27 -06:00
Youngsuk Kim
22325889a4 gfx-auxil: Read on uninitialized buffer may cause UB ( gfx_auxil::read_spirv() ) (#681)
* Report 0101-gfx-auxil to RustSec

* add 'informational = unsound'
2021-08-21 19:38:06 -06:00
github-actions[bot]
2645debec2 Assigned RUSTSEC-2021-0090 to ash (#996)
Co-authored-by: tarcieri <tarcieri@users.noreply.github.com>
2021-08-21 19:37:52 -06:00
Youngsuk Kim
690cf95635 ash: Reading on uninitialized memory may cause UB ( util::read_spv() ) (#680)
* Report 0098-ash to RustSec

* Add 'informational = unsound'
2021-08-21 19:36:30 -06:00
github-actions[bot]
7bf5619877 Assigned RUSTSEC-2021-0089 to raw-cpuid (#995)
Co-authored-by: tarcieri <tarcieri@users.noreply.github.com>
2021-08-21 19:36:17 -06:00