Files
advisory-db/crates/portaudio/RUSTSEC-2016-0003.toml

16 lines
463 B
TOML

[advisory]
id = "RUSTSEC-2016-0003"
package = "portaudio"
date = "2016-08-01"
title = "HTTP download and execution allows MitM RCE"
description = """
The build script in the portaudio crate will attempt to download via HTTP
the portaudio source and build it.
A Mallory in the middle can intercept the download with their own archive
and get RCE.
"""
patched_versions = []
url = "https://github.com/RustAudio/rust-portaudio/issues/144"
keywords = ["ssl", "mitm"]