Commit Graph

1535 Commits

Author SHA1 Message Date
JOE1994
1e1e0538a8 eventio: Input<R>' can send non-Send types to other threads 2021-01-19 10:45:33 -05:00
github-actions[bot]
89b9e10631 Assigned RUSTSEC-2021-0006 to cache (#598)
Co-authored-by: tarcieri <tarcieri@users.noreply.github.com>
2021-01-19 07:45:15 -08:00
Stefan Bühler
97aa97b0b7 cache: exposes internally used raw pointer (#543)
Co-authored-by: Tony Arcieri <bascule@gmail.com>
2021-01-19 07:40:52 -08:00
github-actions[bot]
315e464cd6 Assigned RUSTSEC-2020-0099 to aovec (#596)
Co-authored-by: tarcieri <tarcieri@users.noreply.github.com>
2021-01-19 07:34:42 -08:00
Ammar Askar
c988655410 Add advisory for data race in aovec (#528) 2021-01-19 07:31:18 -08:00
JOE1994
3ee158ea8f data race in lexer::ReaderResult<T, E> 2021-01-19 10:30:32 -05:00
JOE1994
633fd6e295 calamine: access unclaimed/uninitialized memory 2021-01-19 01:11:19 -05:00
JOE1994
5200c9627f data race in ButtplugFutureStateShared 2021-01-19 00:50:33 -05:00
Ammar Askar
85b183d9f1 Add advisory for data race in toolshed 2021-01-18 21:41:55 -08:00
Ammar Askar
4fafd5c990 Add advisory for data race in dces 2021-01-18 21:29:48 -08:00
Ammar Askar
828efa2d4e Add advisory for data race in lever 2021-01-18 21:19:45 -08:00
JOE1994
24f1efd9cc unconditional Sync impl of atomic-option 2021-01-19 00:16:06 -05:00
Ammar Askar
4f4d639438 Add advisory for double-free in fil-ocl 2021-01-18 19:53:42 -08:00
JOE1994
d3a67d2b52 bra: Read on uninitialized buffer 2021-01-18 22:33:36 -05:00
Ammar Askar
a6d6cb7103 Add unmaintained advisory for stderr crate 2021-01-18 19:14:55 -08:00
Jungwon Lim
a68e26e31b Add advisory for data race in hashconsing 2021-01-18 21:48:39 -05:00
Jungwon Lim
a07325e1c1 Add advisory for data race in may_queue 2021-01-18 21:04:11 -05:00
github-actions[bot]
3fbe06486f Assigned RUSTSEC-2020-0098 to rusb (#581)
Co-authored-by: tarcieri <tarcieri@users.noreply.github.com>
2021-01-18 16:23:21 -08:00
Ammar Askar
d7de84eddd Add advisory for data race in rusb (#580) 2021-01-18 16:20:42 -08:00
Ammar Askar
6fb69056e2 Add advisory for data race in conquer-once 2021-01-18 15:44:41 -08:00
Yechan Bae
7423c1a37b Report 0034-model to RustSec 2021-01-18 18:22:24 -05:00
Sergey "Shnatsel" Davidoff
a06ba1740f Merge pull request #576 from RustSec/assign-ids
Assigned RUSTSEC-2020-0097 to xcb
2021-01-18 22:15:44 +01:00
Shnatsel
ea86742059 Assigned RUSTSEC-2020-0097 to xcb 2021-01-18 21:10:35 +00:00
JOE1994
3a722f1f73 av-data: read from arbitrary address in safe API 2021-01-18 16:10:08 -05:00
Sergey "Shnatsel" Davidoff
9804ecca65 Merge pull request #575 from Qwaz/0063-xcb
xcb: Soundness issue with base::Error
2021-01-18 22:10:06 +01:00
Yechan Bae
1613b211a4 Report 0063-xcb to RustSec 2021-01-18 16:07:03 -05:00
Sergey "Shnatsel" Davidoff
9fdc0837de Merge pull request #572 from RustSec/assign-ids
Assigned RUSTSEC-2020-0096 to im
2021-01-18 21:57:10 +01:00
Shnatsel
b2a7af1c9b Assigned RUSTSEC-2020-0096 to im 2021-01-18 20:56:32 +00:00
Sergey "Shnatsel" Davidoff
28f74a84c7 Merge pull request #569 from Qwaz/0025-im
im: TreeFocus lacks bounds on its Send and Sync traits
2021-01-18 21:56:01 +01:00
Sergey "Shnatsel" Davidoff
caf3dee2c1 Merge pull request #570 from RustSec/assign-ids
Assigned RUSTSEC-2021-0005 to glsl-layout
2021-01-18 21:55:34 +01:00
Shnatsel
4cf4c54978 Assigned RUSTSEC-2021-0005 to glsl-layout 2021-01-18 20:55:01 +00:00
Yechan Bae
47061ba310 Report 0025-im to RustSec 2021-01-18 15:50:10 -05:00
Sergey "Shnatsel" Davidoff
4e1c5c4006 Merge pull request #568 from JOE1994/glsl-layout
glsl-layout: double drop upon panic in 'fn map_array'
2021-01-18 21:48:42 +01:00
JOE1994
efb79effca report double drop issue in glsl-layout 2021-01-18 15:41:35 -05:00
Sergey "Shnatsel" Davidoff
854d300690 Merge pull request #566 from RustSec/assign-ids
Assigned RUSTSEC-2021-0004 to lazy-init
2021-01-18 20:55:31 +01:00
Shnatsel
47d589b0bd Assigned RUSTSEC-2021-0004 to lazy-init 2021-01-18 19:54:50 +00:00
Sergey "Shnatsel" Davidoff
5bb2d97363 Merge pull request #565 from niklasf/lazy-init
lazy-init: Missing Send bound for Lazy (khuey/lazy-init#9)
2021-01-18 20:54:19 +01:00
Sergey "Shnatsel" Davidoff
6703edaf88 apply review changes 2021-01-18 20:51:26 +01:00
Niklas Fiekas
6ea698b85d lazy-init: Missing Send bound for Lazy (khuey/lazy-init#9) 2021-01-17 21:41:50 +01:00
Yechan Bae
b08a98acc7 Fix typo in http CVE number (#564) 2021-01-15 07:32:15 -08:00
Jeffrey Robinson
14b29c77eb Typo in RUSTSEC-2020-0013 (#562)
Minor typo.
2021-01-14 09:57:27 -08:00
Tony Arcieri
8e1ad08eee Publish Web: fix YAML indenting (#559) 2021-01-13 06:06:20 -08:00
Tony Arcieri
50451dd5b8 Publish Web: fix rustsec-admin install (#558)
We do still need to check if `rustsec-admin` is installed, as an error
is returned if it's already installed.
2021-01-13 06:04:12 -08:00
Tony Arcieri
a3efac5977 Add "Publish Web" GitHub Action (#557)
Automatically rebuilds the contents of the `gh-pages` branch on merge
2021-01-13 06:00:38 -08:00
Matt Brubeck
7feb037b84 RUSTSEC-2020-0017.md (use-after-free in internment) is fixed (#554)
The vulnerability in this report was fixed in internment 0.4.0.  For details, see
https://github.com/droundy/internment/issues/11#issuecomment-758862385.
2021-01-12 11:05:27 -08:00
Sergey "Shnatsel" Davidoff
fa47ec0c0b Merge pull request #553 from RustSec/assign-ids
Assigned RUSTSEC-2021-0003 to smallvec
2021-01-08 19:15:06 +01:00
Shnatsel
519862dda6 Assigned RUSTSEC-2021-0003 to smallvec 2021-01-08 18:14:52 +00:00
Sergey "Shnatsel" Davidoff
5851ec6321 Merge pull request #552 from mbrubeck/smallvec
smallvec: Buffer overflow in insert_many
2021-01-08 19:14:20 +01:00
Matt Brubeck
dfe84fd15f smallvec: Buffer overflow in insert_many 2021-01-08 09:57:23 -08:00
Sergey "Shnatsel" Davidoff
aa3b156442 do not suggest pretty_assertions as an alternative
because it depends on `difference`
2021-01-07 05:01:36 +01:00