Files
advisory-db/crates/rusqlite/RUSTSEC-2020-0014.md
2021-01-04 09:02:59 -08:00

873 B

[advisory]
id = "RUSTSEC-2020-0014"
package = "rusqlite"
aliases = [
    "CVE-2020-35866",
    "CVE-2020-35867",
    "CVE-2020-35868",
    "CVE-2020-35869",
    "CVE-2020-35870",
    "CVE-2020-35871",
    "CVE-2020-35872",
    "CVE-2020-35873",
]
date = "2020-04-23"
url = "https://github.com/rusqlite/rusqlite/releases/tag/0.23.0"

[affected.functions]
"rusqlite::Connection::get_aux" = ["< 0.23.0"]
"rusqlite::Connection::set_aux" = ["< 0.23.0"]
"rusqlite::session::Session::attach" = ["< 0.23.0"]
"rusqlite::session::Session::diff" = ["< 0.23.0"]
"rusqlite::trace::log" = ["< 0.23.0"]
"rusqlite::vtab::create_module" = ["< 0.23.0"]

[versions]
patched = [">= 0.23.0"]

Various memory safety issues

Several memory safety issues have been uncovered in an audit of rusqlite.

See https://github.com/rusqlite/rusqlite/releases/tag/0.23.0 for a complete list.