Commit Graph

45 Commits

Author SHA1 Message Date
Tony Arcieri
875d4d5fdd Assign RUSTSEC-2018-0008 to slice-deque
Original PR: https://github.com/RustSec/advisory-db/pull/70
2018-12-06 09:18:37 -08:00
gnzlbg
4effd1975e Add keywords 2018-12-06 17:58:48 +01:00
gnzlbg
895fe023df Add advisory for slice-deque 2018-12-06 17:53:12 +01:00
Tony Arcieri
487ffe4728 Fix "date:" field on RUSTSEC-2018-0007
It appears it was mistakenly filed as being in 2017
2018-10-14 09:53:19 -07:00
Tony Arcieri
aa901622d6 Assign RUSTSEC-2018-0007 to trust-dns-proto
Original PR: https://github.com/RustSec/advisory-db/pull/62
2018-10-13 18:31:34 -07:00
Tony Arcieri
b825af523e Merge branch 'master' into trust-dns-proto-0-4-3 2018-10-13 18:14:24 -07:00
Tony Arcieri
89aab75c1b Assign RUSTSEC-2018-0006 to yaml-rust
Original PR: https://github.com/RustSec/advisory-db/pull/60
2018-10-13 18:09:39 -07:00
Tony Arcieri
2c3880df0d Merge branch 'master' into yaml-rust-advisory 2018-10-13 17:32:09 -07:00
Tony Arcieri
ee579432c6 Assign RUSTSEC-2018-0005 to serde_yaml
Original PR: https://github.com/RustSec/advisory-db/pull/61
2018-10-13 16:24:33 -07:00
Ossi Herrala
d6b9d03e45 Stack overflow in Trust-DNS when parsing DNS packet 2018-10-11 15:55:18 +03:00
Konrad Borowski
f22c3798f6 Add advisory for serde_yaml 2018-09-17 08:59:36 +02:00
Konrad Borowski
dce22c22b2 Add advisory for yaml-rust 2018-09-17 08:48:40 +02:00
Tony Arcieri
575dc9a705 Assign RUSTSEC-2018-0004 to claxon
Original PR:

https://github.com/RustSec/advisory-db/pull/54
2018-08-25 07:11:55 -07:00
Ruud van Asseldonk
a79e12f482 Add advisory for Claxon 0.3.2 and 0.4.1 2018-08-25 12:36:22 +02:00
Tony Arcieri
1296249cfb RUSTSEC-2016-0002.toml: use 'affected_os' attribute
Replaces the 'affected_platforms' attribute in rustsec v0.9.
2018-07-26 21:02:15 -07:00
Tony Arcieri
2d9a2632a7 Keywords
Documents the new `keywords` attribute and adds keywords to all current
advisories. These can be consumed by the web UI.
2018-07-24 16:02:35 -07:00
Tony Arcieri
2632340526 Affected Platforms
Documents the use of the `affected_platforms` attribute in advisories,
and adds it to a relevant advisory.
2018-07-24 15:53:43 -07:00
Tony Arcieri
07219b8d17 Assign RUSTSEC-2016-0002 to hyper
Original PR:

https://github.com/RustSec/advisory-db/pull/18
2018-07-24 12:33:49 -07:00
Tony Arcieri
8678a77455 Advisory: hyper HTTPS MitM due to lack of hostname verification 2018-07-24 12:03:59 -07:00
Tony Arcieri
09e3a9eb76 Assign RUSTSEC-2016-0001 to openssl
Original PR:

https://github.com/RustSec/advisory-db/pull/19
2018-07-24 10:48:20 -07:00
Tony Arcieri
72a4178ca1 Advisory: openssl <0.9.0 may be vulnerable to MitM due to weak defaults 2018-07-24 10:47:29 -07:00
Tony Arcieri
cb81d3ceaa Rename "dwf" TOML tag to "aliases" (closes #36)
Nobody knows what "dwf" is, and the data isn't presently consumed or
surfaced by the `rustsec` crate, so we (hopefully) can rename it without
breaking anything.
2018-07-21 19:47:30 -07:00
Tony Arcieri
79fd13ac6f crates: Add 'id' attribute to all advisories
This is needed to parse them with serde directly from these files (as
opposed to using Advisories.toml)
2018-07-21 15:22:39 -07:00
Matt Brubeck
194883b71e More patched versions released for smallvec 2018-07-20 10:31:28 -07:00
Tony Arcieri
0a1d62c88d Advisories.toml: Fix RUSTSEC-2018-0002
`RUSTSEC-2018-0002` was previously assigned to `tar`, but never added to
`Advisories.toml`.

The merge workflow for this could definitely use some
improvements/automation.
2018-07-19 19:26:08 -07:00
Tony Arcieri
7855ffa911 Assign RUSTSEC-2018-0003 to smallvec
Original PR:

https://github.com/RustSec/advisory-db/pull/30
2018-07-19 19:20:54 -07:00
Matt Brubeck
fd11c62bc5 Advisory: Possible double free in SmallVec::insert_many
For details, see:

* servo/rust-smallvec#96 - original bug report
* servo/rust-smallvec#103 - fix
2018-07-19 15:00:38 -07:00
Alex Crichton
1e553ef856 Aribtrary filesystem writes in tar 0.4.15 and older
More details inside!
2018-06-29 13:19:26 -07:00
Tony Arcieri
3c0458d26b Assign RUSTSEC-2018-0001 to untrusted
Original PR:

https://github.com/RustSec/advisory-db/pull/24
2018-06-26 00:13:01 +01:00
Ossi Herrala
f5c8d09051 An integer underflow in untrusted 0.6.1 and older 2018-06-25 21:56:39 +03:00
Corey Farwell
18d848d456 RUSTSEC-2017-0004 is also known as CVE-2017-1000430 2017-12-29 13:49:40 -08:00
Tony Arcieri
ce29282ad4 RUSTSEC-2017-0001 is also known as CVE-2017-1000168 2017-08-24 08:45:54 -07:00
Tony Arcieri
fafc60ceee Assign RUSTSEC-2017-0005 to cookie
Original PR:

https://github.com/RustSec/advisory-db/pull/22
2017-05-08 07:56:46 -07:00
Erick Tryzelaar
bfcf9e99c2 Advisory: cookie denial of service 2017-05-07 16:06:21 -07:00
Tony Arcieri
524d876a8a Assign RUSTSEC-2017-0004 to base64
Original PR:

https://github.com/RustSec/advisory-db/pull/21
2017-05-04 09:52:29 -07:00
Andrew Ayer
b9a0862f48 Advisory: base64 heap-based buffer overflow 2017-05-03 17:05:46 -07:00
Tony Arcieri
e6b5f1a74f Assign RUSTSEC-2017-0003 to security-framework
Original PR:

https://github.com/RustSec/advisory-db/pull/16
2017-03-15 22:34:43 -07:00
Steven Fackler
ffb475d466 Advisory: security-framework hostname verification bypass 2017-03-15 11:47:14 -07:00
Tony Arcieri
e867ef7194 Assign RUSTSEC-2017-0002 to hyper
Original PR:

https://github.com/RustSec/advisory-db/pull/12
2017-02-28 09:02:18 -08:00
Sean McArthur
4597f51b45 add advisory for hyper message splitting vulnerability 2017-02-27 15:13:17 -08:00
Tony Arcieri
05af1866b1 Revert "Merge pull request #8 from RustSec/rename-package-to-crate-name"
Cargo uses "package" in Cargo.lock, so there is wisdom to using "package"
instead of "crate_name"

This reverts commit 986c090c06, reversing
changes made to 9556f0fdee.
2017-02-26 00:26:22 -08:00
Tony Arcieri
f4dbb0d82c Rename package TOML attribute to crate_name
The correct name for a Rust package is a "crate", so something with "crate" is
less ambiguous than "package".

However, "crate" itself is a Rust keyword. To avoid clashes in Rust code which
uses this same attribute name, "crate_name" can be used instead unambigously.
2017-02-25 23:13:36 -08:00
Tony Arcieri
dc3301d1e4 Add date to RUSTSEC-2017-0001 2017-02-25 16:47:52 -08:00
Tony Arcieri
6f3b266664 Assign RUSTSEC-2017-0001 to sodiumoxide
Original PR:

https://github.com/RustSec/advisory-db/pull/4
2017-02-25 16:46:26 -08:00
Tony Arcieri
1a18a429fc Advisory: sodiumoxide degenerate public keys
Fixed in sodiumoxide 0.0.14.

See: https://github.com/dnaq/sodiumoxide/issues/154
2017-02-25 16:28:44 -08:00