Jesse Szwedko
d4c65da07d
Correct year for CVE-2022-21658 ( #1157 )
...
I accidentally put 2021.
Signed-off-by: Jesse Szwedko <jesse@szwedko.me >
2022-01-20 22:12:36 -05:00
Jesse Szwedko
aad861dd0f
Add advisory for CVE-2022-21658 ( #1155 )
...
Closes: https://github.com/rustsec/advisory-db/issues/1154
Signed-off-by: Jesse Szwedko <jesse@szwedko.me >
2022-01-21 02:54:24 +01:00
github-actions[bot]
bf972ed7d4
Assigned RUSTSEC-2022-0003 to ammonia ( #1153 )
...
Co-authored-by: Shnatsel <Shnatsel@users.noreply.github.com >
2022-01-19 23:35:01 +01:00
Michael Howell
770c8cadd4
Add rust-ammonia/ammonia#147 ( #1152 )
2022-01-19 23:33:28 +01:00
Jan Zerebecki
2e646db508
Add CVE to RUSTSEC-2021-0124 ( #1149 )
2022-01-13 23:33:38 +03:00
github-actions[bot]
36e44b1fb3
Assigned RUSTSEC-2022-0002 to dashmap ( #1148 )
...
Co-authored-by: Shnatsel <Shnatsel@users.noreply.github.com >
2022-01-13 19:31:06 +03:00
baptiste0928
61d8acaf87
Undefined behavior in dashmap ( #1146 )
...
* Create advisory for dashmap
* Update dashmap advisory
* Fix typo
Co-authored-by: Léo Lanteri Thauvin <leseulartichaut@gmail.com >
* Add memory-exposure category
* Add affected functions
Co-authored-by: Léo Lanteri Thauvin <leseulartichaut@gmail.com >
2022-01-13 19:28:39 +03:00
Tony Arcieri
14b4f22897
RUSTSEC-2016-0015: remove sodiumoxide recommendation ( #1145 )
...
`sodiumoxide` is unmaintained itself. See #1090 .
We haven't filed a specific unmaintained crate advisory for it yet, but probably should.
2022-01-09 13:07:15 -07:00
Tony Arcieri
977984668a
README.md: bump maintained date
2022-01-05 09:03:22 -07:00
github-actions[bot]
9997408c08
Assigned RUSTSEC-2022-0001 to lmdb ( #1143 )
...
Co-authored-by: tarcieri <tarcieri@users.noreply.github.com >
2022-01-05 09:02:27 -07:00
Jake Shadle
0bc3195338
Add unmaintained advisory for lmdb ( #1142 )
2022-01-05 08:52:21 -07:00
github-actions[bot]
dcf8fb2a44
Assigned RUSTSEC-2021-0134 to rental ( #1137 )
...
Co-authored-by: alex <alex@users.noreply.github.com >
2021-12-27 14:44:42 -05:00
Ben Kimock
2b51ce8274
Report that rental is no longer maintained ( #1136 )
2021-12-27 14:43:25 -05:00
github-actions[bot]
de2da25935
Assigned RUSTSEC-2020-0160 to shamir ( #1135 )
...
Co-authored-by: Shnatsel <Shnatsel@users.noreply.github.com >
2021-12-27 14:42:26 -05:00
Ben Kimock
a20a779bf7
Turn the issue about shamir into an advisory ( #1134 )
2021-12-27 20:28:54 +01:00
github-actions[bot]
1ea676a614
Assigned RUSTSEC-2021-0133 to cargo-download ( #1133 )
...
Co-authored-by: Shnatsel <Shnatsel@users.noreply.github.com >
2021-12-25 19:20:22 +01:00
pinkforest(she/her)
7f0874b516
Mark cargo-download unmaintained ( #1132 )
2021-12-25 19:04:31 +01:00
Ben Kimock
3952f343f1
Mark arrow advisories as fixed in https://github.com/apache/arrow-rs/issues/817 ( #1131 )
2021-12-22 16:15:54 -05:00
github-actions[bot]
dd7d3d726a
Assigned RUSTSEC-2021-0132 to compu-brotli-sys ( #1130 )
...
Co-authored-by: Shnatsel <Shnatsel@users.noreply.github.com >
2021-12-21 23:27:44 +01:00
Sergey "Shnatsel" Davidoff
dc5ced1155
CVE-2020-8927 for compu-brotli-sys ( #1129 )
2021-12-21 23:26:29 +01:00
github-actions[bot]
32b107c4c6
Assigned RUSTSEC-2021-0131 to brotli-sys ( #1128 )
...
Co-authored-by: Shnatsel <Shnatsel@users.noreply.github.com >
2021-12-21 21:51:30 +01:00
Sergey "Shnatsel" Davidoff
94bde4a325
Brotli CVE-2020-8927 redux ( #1127 )
...
* Create RUSTSEC-0000-0000.md
* wording
2021-12-21 21:48:42 +01:00
github-actions[bot]
ca9497a45b
Assigned RUSTSEC-2021-0130 to lru ( #1126 )
...
Co-authored-by: Shnatsel <Shnatsel@users.noreply.github.com >
2021-12-21 16:50:24 +01:00
Ossi Herrala
2fc8681c0e
Add use after free advisory for lru crate ( #1125 )
...
* Add use after free advisory for lru crate
* Add blockquotes
* Update RUSTSEC-0000-0000.md
Co-authored-by: Sergey "Shnatsel" Davidoff <shnatsel@gmail.com >
2021-12-21 16:47:42 +01:00
github-actions[bot]
bfcafe5727
Assigned RUSTSEC-2021-0129 to openssl-src ( #1123 )
...
Co-authored-by: Shnatsel <Shnatsel@users.noreply.github.com >
2021-12-15 01:18:24 +01:00
Alexis Mousset
ee8bb37fb1
Add CVE-2021-4044 for openssl-src ( #1122 )
2021-12-15 01:13:03 +01:00
github-actions[bot]
6d06054e82
Assigned RUSTSEC-2021-0128 to rusqlite ( #1120 )
...
Co-authored-by: Shnatsel <Shnatsel@users.noreply.github.com >
2021-12-09 01:29:19 +01:00
Thom Chiovoloni
ef9463d5a7
Report rusqlite closure lifetime issue ( #1117 )
2021-12-09 01:28:00 +01:00
Emil Gardström
1204636ca5
correct formatting for lists in RUSTSEC-2021-0127 ( #1116 )
2021-12-01 15:04:55 +01:00
github-actions[bot]
1c4b2d56c3
Assigned RUSTSEC-2021-0127 to serde_cbor ( #1115 )
...
Co-authored-by: tarcieri <tarcieri@users.noreply.github.com >
2021-11-30 07:21:27 -07:00
Jose Santos
79158e0a4d
serde_cbor is unmaintained ( #1114 )
2021-11-30 07:16:10 -07:00
github-actions[bot]
24987956da
Assigned RUSTSEC-2021-0126 to rust-embed ( #1113 )
...
Co-authored-by: Shnatsel <Shnatsel@users.noreply.github.com >
2021-11-29 19:32:40 +01:00
5225225
de35d2ee12
Add advisory for rust-embed path traversal ( #1112 )
2021-11-29 19:25:01 +01:00
Linus Probert
825e7ae54c
Adds maintained alternative to slice_deque ( #1109 )
2021-11-18 07:04:01 -07:00
github-actions[bot]
c3e02b1dc8
Assigned RUSTSEC-2021-0125 to simple_asn1 ( #1108 )
...
Co-authored-by: Shnatsel <Shnatsel@users.noreply.github.com >
2021-11-18 01:32:59 +01:00
Nick Mathewson
c98000195b
Security advisory on simple_asn1 version 0.6.0 ( #1103 )
...
* Security advisory on simple_asn1 version 0.6.0
The maintainer has acknowledged and fixed this issue; see
https://github.com/acw/simple_asn1/pull/28 .
* fixup! Security advisory on simple_asn1 version 0.6.0
Try to fix lint errors.
2021-11-18 01:29:09 +01:00
github-actions[bot]
3af7a839b1
Assigned RUSTSEC-2021-0124 to tokio ( #1107 )
...
Co-authored-by: Shnatsel <Shnatsel@users.noreply.github.com >
2021-11-17 00:11:14 +01:00
Eliza Weisman
5f68bbad79
Add advisory for tokio-rs/tokio#4225 ( #1106 )
...
* Add advisory for tokio-rs/tokio#4225
If a `tokio::sync::oneshot` channel is closed (via the
[`oneshot::Receiver::close`] method), a data race may occur if the
`oneshot::Sender::send` method is called while the corresponding
`oneshot::Receiver` is `await`ed or calling `try_recv`.
When these methods are called concurrently on a closed channel, the two halves
of the channel can concurrently access a shared memory location, resulting in a
data race. This has been observed to [cause memory corruption][corruption].
Note that the race only occurs when **both** halves of the channel are used
after one half has called `close`. Code where `close` is not used, or where the
`Receiver` is not `await`ed and `try_recv` is not called after calling `close`,
is not affected.
See tokio-rs/tokio#4225 for more details.
This issue was patched in v1.13.1. The patch was backported to the current
LTS version (v1.8.x) in release v1.8.4.
* Update crates/tokio/RUSTSEC-0000-0000.md
Co-authored-by: Tony Arcieri <bascule@gmail.com >
* fix toml lint
whoops
* Update crates/tokio/RUSTSEC-0000-0000.md
* Update crates/tokio/RUSTSEC-0000-0000.md
Co-authored-by: Tony Arcieri <bascule@gmail.com >
2021-11-17 00:02:09 +01:00
dylni
2a4f5887aa
Add CVE for RUSTSEC-2021-0123 ( #1105 )
2021-11-15 06:53:17 -07:00
github-actions[bot]
dee60c20d1
Assigned RUSTSEC-2021-0123 to fruity ( #1104 )
...
Co-authored-by: Shnatsel <Shnatsel@users.noreply.github.com >
2021-11-15 01:29:25 +01:00
dylni
d5184e35e3
Add fruity advisory for nvzqz/fruity#14 ( #1102 )
...
* Add fruity advisory for nvzqz/fruity#14
* Fix lint error
* Fix lint error
* Add an impact section
2021-11-15 01:26:35 +01:00
Tony Arcieri
26a6973ff1
Bump rustsec-admin to v0.6.0 ( #1101 )
2021-11-13 11:38:33 -07:00
github-actions[bot]
9e93a3df4a
Assigned RUSTSEC-2021-0122 to flatbuffers ( #1100 )
...
Co-authored-by: tarcieri <tarcieri@users.noreply.github.com >
2021-11-07 10:53:20 -07:00
Jorge Leitao
79b4d8e547
Add flatbuffers advisory for flatbuffers#6627 ( #1093 )
2021-11-07 10:51:34 -07:00
Alexander Kjäll
f4a8973706
add cve info to advisories ( #1099 )
...
* add cve info to advisories
* Put `aliases` field in the proper place
It should not be under `[versions]`
* move `aliases` to the proper place
Co-authored-by: Sergey "Shnatsel" Davidoff <shnatsel@gmail.com >
2021-11-06 21:37:35 +01:00
Tony Arcieri
5ad6e60967
Bump rustsec-admin to v0.5.3 ( #1091 )
2021-10-22 08:28:51 -06:00
Alexis Mousset
8c05fea5fa
Add cvss information from nvd ( #1085 )
2021-10-19 16:14:35 -06:00
Jacob Pratt
d8701fad2d
Add missing method to time vulnerability ( #1086 )
2021-10-19 16:13:58 -06:00
Alexis Mousset
0c762d06a8
Add CVE alias for RUSTSEC-2021-0069 ( #1087 )
2021-10-19 21:56:47 +02:00
github-actions[bot]
8e29664694
Assigned RUSTSEC-2021-0121 to crypto2 ( #1084 )
...
Co-authored-by: tarcieri <tarcieri@users.noreply.github.com >
2021-10-18 10:22:07 -06:00