Commit Graph

3 Commits

Author SHA1 Message Date
Alexis Mousset
e1a39a6085 Sync advisories ids from GitHub (#1881) 2024-02-10 10:57:43 -05:00
github-actions[bot]
7b510556ab Assigned RUSTSEC-2023-0064 to gix-transport (#1790)
Co-authored-by: Shnatsel <Shnatsel@users.noreply.github.com>
2023-09-25 12:04:51 +00:00
Sebastian Thiel
851e5c9638 Add notice to gix-transport crate (#1789)
* Add vulnerability for gix-transport crate

Reproducer with `gix` (CLI) v0.29

* `gix clone 'ssh://-oProxyCommand=open$IFS-aCalculator/foo'`
    - This will launch a calculator on OSX.

Fixed in `gix` (CLI) v0.30.

See https://secure.phabricator.com/T12961 for more details.

This issue was discovered by @vin01 whom I thank for their diligence!

* Add credits to researcher who found the issue: vin01

https://github.com/vin01
2023-09-25 12:03:35 +00:00