Commit Graph

1270 Commits

Author SHA1 Message Date
github-actions[bot]
ca8a60b7be Assigned RUSTSEC-2021-0044 to rocket (#838)
Co-authored-by: alex <alex@users.noreply.github.com>
2021-03-26 10:23:59 -04:00
Ammar Askar
8f7af7c6c5 [patched] Add advisory for use-after-free in rocket (#834)
* Add advisory for use-after-free in rocket

* Clarify that the UAF can only happen during or after unwinding
2021-03-26 10:17:31 -04:00
github-actions[bot]
40e78f4922 Assigned RUSTSEC-2021-0043 to uu_od (#837)
Co-authored-by: alex <alex@users.noreply.github.com>
2021-03-26 09:07:17 -04:00
Ammar Askar
6265d0dc36 Add advisory for uninitialized exposure in uu_od (#836) 2021-03-26 09:05:12 -04:00
Sergey "Shnatsel" Davidoff
cc8f4f0615 Merge pull request #833 from RustSec/assign-ids
Assigned RUSTSEC-2021-0042 to insert_many
2021-03-26 07:44:58 +01:00
Shnatsel
996a3eca3b Assigned RUSTSEC-2021-0042 to insert_many 2021-03-26 06:43:47 +00:00
Sergey "Shnatsel" Davidoff
a1aa708b13 Merge pull request #832 from ammaraskar/insert_many
Add advisory for double-free in insert_many
2021-03-26 07:43:21 +01:00
Ammar Askar
c742f10bbd Add advisory for double-free in insert_many 2021-03-25 22:57:00 -07:00
github-actions[bot]
3ddeb5c6cf Assigned RUSTSEC-2021-0041 to parse_duration (#829)
Co-authored-by: tarcieri <tarcieri@users.noreply.github.com>
2021-03-24 21:45:20 -07:00
Disconnect3d
3864def6bf parse_duration: parse DoS through payloads with big exponent (#827) 2021-03-24 21:43:09 -07:00
Yechan Bae
cda5b3ffd4 Update CVE numbers (#828) 2021-03-19 14:21:58 -07:00
Tony Arcieri
f960a50364 Have master-to-main mirror force push (#822)
Not sure quote what the problem is, but it's erroring:
https://github.com/RustSec/advisory-db/runs/2051631730?check_suite_focus=true
2021-03-07 10:44:24 -08:00
Tony Arcieri
7b10b2e7a1 Fix main -> master mirroring (#821) 2021-03-07 10:39:38 -08:00
Tony Arcieri
2c43b7001e Rename master branch to main (#820)
Per #312
2021-03-07 10:29:41 -08:00
Tony Arcieri
ad84df90d7 Mirror 'main' branch to 'master' (#819)
The 'master' branch has been renamed to 'main' per:

https://github.com/RustSec/advisory-db/issues/312

However older clients are still consuming the 'master' branch.

This commit adds a GitHub Actions job which mirrors the 'main' branch to
'master' to continue supporting these older clients.
2021-03-07 10:18:34 -08:00
Tony Arcieri
0487b3fc94 README.md: fix "Report Vulnerability" button (#818) 2021-03-07 09:40:34 -08:00
Sergey "Shnatsel" Davidoff
e391658d24 Merge pull request #817 from RustSec/assign-ids
Assigned RUSTSEC-2021-0040 to arenavec
2021-03-07 16:10:25 +01:00
Shnatsel
0bc081bb02 Assigned RUSTSEC-2021-0040 to arenavec 2021-03-07 15:10:05 +00:00
Sergey "Shnatsel" Davidoff
bcdb169985 Merge pull request #815 from JOE1994/0109-arenavec
arenavec: potential double drop or uninitialized memory drop upon panic
2021-03-07 16:09:38 +01:00
Sergey "Shnatsel" Davidoff
caf713f271 Merge pull request #816 from RustSec/assign-ids
Assigned RUSTSEC-2021-0039 to endian_trait
2021-03-07 16:09:17 +01:00
Shnatsel
f2f59e4ec9 Assigned RUSTSEC-2021-0039 to endian_trait 2021-03-07 15:08:31 +00:00
Sergey "Shnatsel" Davidoff
93a881f6fc Merge pull request #814 from JOE1994/0090-endian_trait
endian_trait: panic in user-provided `Endian` impl triggers double drop of T
2021-03-07 16:08:04 +01:00
Youngsuk Kim
c2248b0eef arenavec: update advisory title to clarify issue 2021-03-07 09:21:06 -05:00
JOE1994
ef52d55d34 Report 0109-arenavec to RustSec 2021-03-07 00:57:30 -05:00
JOE1994
3205a0919e Report 0090-endian_trait to RustSec 2021-03-07 00:29:24 -05:00
Sergey "Shnatsel" Davidoff
146a642232 Merge pull request #813 from RustSec/assign-ids
Assigned RUSTSEC-2021-0038 to fltk
2021-03-06 20:31:10 +01:00
Shnatsel
805270dce5 Assigned RUSTSEC-2021-0038 to fltk 2021-03-06 19:30:02 +00:00
Sergey "Shnatsel" Davidoff
8208a960b6 Merge pull request #812 from MoAlyousef/master
add known issues with fltk
2021-03-06 20:29:38 +01:00
MoAlyousef
a84dbc5d57 formatting 2021-03-06 22:22:50 +03:00
MoAlyousef
35e0ea59a6 replace with keywords 2021-03-06 22:21:27 +03:00
Mohammed Alyousef
d07de9975d Update RUSTSEC-0000-0000.md 2021-03-06 22:02:26 +03:00
Mohammed Alyousef
5ce4048734 Update RUSTSEC-0000-0000.md 2021-03-06 22:02:14 +03:00
MoAlyousef
a33c05d20a add fltk advisory 2021-03-06 22:01:14 +03:00
Ammar Askar
ae1107e479 Update rustsec-admin version to use new website generator (#810) 2021-03-06 09:39:36 -08:00
Sergey "Shnatsel" Davidoff
2821ca0c6c Merge pull request #811 from RustSec/assign-ids
Assigned RUSTSEC-2021-0037 to diesel
2021-03-05 14:42:53 +01:00
Shnatsel
dd560c650f Assigned RUSTSEC-2021-0037 to diesel 2021-03-05 13:42:28 +00:00
Sergey "Shnatsel" Davidoff
34e986372a Merge pull request #809 from weiznich/master
Report use-after-free issue in diesels sqlite backend
2021-03-05 14:41:59 +01:00
Georg Semmler
c31f016dce Update crates/diesel/RUSTSEC-0000-0000.md
Co-authored-by: Sergey "Shnatsel" Davidoff <shnatsel@gmail.com>
2021-03-05 12:18:06 +00:00
Georg Semmler
e5c10bccb9 Update crates/diesel/RUSTSEC-0000-0000.md
Co-authored-by: Sergey "Shnatsel" Davidoff <shnatsel@gmail.com>
2021-03-05 09:12:08 +00:00
Georg Semmler
4f30ae8e72 Report use-after-free issue in diesels sqlite backend 2021-03-04 19:15:19 +01:00
Sergey "Shnatsel" Davidoff
68ccfc5bab Merge pull request #808 from RustSec/assign-ids
Assigned RUSTSEC-2021-0036 to internment
2021-03-04 16:18:08 +01:00
Shnatsel
423ca50401 Assigned RUSTSEC-2021-0036 to internment 2021-03-04 15:16:03 +00:00
Sergey "Shnatsel" Davidoff
12b47a00c4 Merge pull request #807 from JOE1994/0162-internment
internment: Intern<T>: Data race allowed on T
2021-03-04 16:15:28 +01:00
JOE1994
ac5a6f9239 Report 0162-internment to RustSec 2021-03-04 10:07:34 -05:00
Sergey "Shnatsel" Davidoff
c58eda204b Merge pull request #806 from RustSec/assign-ids
Assigned RUSTSEC-2020-0147 to rulinalg
2021-03-04 14:58:35 +01:00
Shnatsel
0f0dbd0675 Assigned RUSTSEC-2020-0147 to rulinalg 2021-03-04 13:58:02 +00:00
Sergey "Shnatsel" Davidoff
e4cc2dfc24 Merge pull request #801 from ammaraskar/rulinalg
Add unmaintained advisory for rulinalg crate
2021-03-04 14:57:11 +01:00
github-actions[bot]
e93938cb63 Assigned RUSTSEC-2021-0035 to quinn (#805)
Co-authored-by: alex <alex@users.noreply.github.com>
2021-03-04 08:01:02 -05:00
Dirkjan Ochtman
a0ec5819c8 Add advisory for invalid layout assumptions in quinn (#804) 2021-03-04 07:59:10 -05:00
Sergey "Shnatsel" Davidoff
03292ba192 Merge pull request #803 from RustSec/assign-ids
Assigned RUSTSEC-2021-0034 to office
2021-03-03 19:15:35 +01:00