Files
advisory-db/crates
Andrew Gallant ec6dbf077c crates/grep-cli: add advisory for arbitrary binary execution on Windows (#939)
* crates/grep-cli: add advisory for arbitrary binary execution on Windows

Ref https://github.com/BurntSushi/ripgrep/issues/1773

* drop commented out field

* crates/grep-cli: add more details about mitigation

Instead of dancing around it, we just say it: the main issue is that
std::process::Command will resolve relative binary names with respect to
the CWD first, because it just uses the Windows API for this.

More specifically, we call out the two particular mitigations that are
now in place.

Co-authored-by: Sergey "Shnatsel" Davidoff <shnatsel@gmail.com>
2021-06-15 00:42:25 +02:00
..
2021-02-25 20:00:25 -05:00
2021-01-04 09:02:59 -08:00
2021-01-04 09:02:59 -08:00
2021-01-04 09:02:59 -08:00
2021-01-04 09:02:59 -08:00
2021-04-13 14:10:09 -07:00
2021-01-04 09:02:59 -08:00
2021-02-25 20:00:25 -05:00
2021-04-13 14:10:09 -07:00
2021-01-04 09:02:59 -08:00
2021-02-25 20:00:25 -05:00
2021-02-25 20:00:25 -05:00
2021-02-25 20:00:25 -05:00
2021-02-25 20:00:25 -05:00
2021-03-19 14:21:58 -07:00
2021-01-04 09:02:59 -08:00
2021-01-04 09:02:59 -08:00
2021-02-25 20:00:25 -05:00
2021-01-04 09:02:59 -08:00
2021-01-04 09:02:59 -08:00
2021-02-25 20:00:25 -05:00
2021-03-19 14:21:58 -07:00
2021-02-25 20:00:25 -05:00
2021-02-25 20:00:25 -05:00
2021-01-04 09:02:59 -08:00
2021-02-25 20:00:25 -05:00
2021-03-26 19:11:23 +00:00
2021-01-04 09:02:59 -08:00
2021-02-25 20:00:25 -05:00
2021-02-25 20:00:25 -05:00
2021-01-04 09:02:59 -08:00
2021-03-19 14:21:58 -07:00
2021-01-04 09:02:59 -08:00
2021-04-13 14:10:09 -07:00
2021-02-25 20:00:25 -05:00
2021-05-11 18:59:58 -07:00
2021-01-04 09:02:59 -08:00
2021-02-25 20:00:25 -05:00
2021-01-04 09:02:59 -08:00
2021-03-19 14:21:58 -07:00
2021-01-04 09:02:59 -08:00
2021-02-25 20:00:25 -05:00
2021-02-25 20:00:25 -05:00
2021-02-25 20:00:25 -05:00
2021-01-15 07:32:15 -08:00
2021-04-13 14:10:09 -07:00
2021-02-25 20:00:25 -05:00
2021-01-04 09:02:59 -08:00
2021-04-13 14:10:09 -07:00
2021-03-19 14:21:58 -07:00
2021-02-25 20:00:25 -05:00
2021-02-25 20:00:25 -05:00
2021-02-01 12:57:26 +01:00
2021-01-04 09:02:59 -08:00
2021-02-25 20:00:25 -05:00
2021-02-25 20:00:25 -05:00
2021-01-04 09:02:59 -08:00
2021-01-04 09:02:59 -08:00
2021-02-25 20:00:25 -05:00
2021-01-04 09:02:59 -08:00
2021-02-25 20:00:25 -05:00
2021-03-19 14:21:58 -07:00
2021-01-04 09:02:59 -08:00
2021-02-25 20:00:25 -05:00
2021-01-04 09:02:59 -08:00
2021-01-04 09:02:59 -08:00
2021-01-04 09:02:59 -08:00
2021-01-04 09:02:59 -08:00
2021-01-04 09:02:59 -08:00
2021-04-13 14:10:09 -07:00
2021-01-04 09:02:59 -08:00
2021-04-13 14:10:09 -07:00
2020-10-25 12:51:46 -07:00
2021-02-25 20:00:25 -05:00
2021-01-04 09:02:59 -08:00
2021-01-04 09:02:59 -08:00
2021-03-19 14:21:58 -07:00
2021-02-25 20:00:25 -05:00
2021-02-25 20:00:25 -05:00
2021-02-25 20:00:25 -05:00
2021-04-13 14:10:09 -07:00
2021-01-04 09:02:59 -08:00
2021-04-13 14:10:09 -07:00
2021-02-25 20:00:25 -05:00
2021-01-04 09:02:59 -08:00
2021-03-19 14:21:58 -07:00
2021-01-04 09:02:59 -08:00
2021-01-04 09:02:59 -08:00
2021-02-14 12:08:19 +00:00
2021-04-13 14:10:09 -07:00
2021-02-25 20:00:25 -05:00
2021-01-04 09:02:59 -08:00
2021-01-04 09:02:59 -08:00
2021-03-19 14:21:58 -07:00
2021-04-13 14:10:09 -07:00
2021-01-04 09:02:59 -08:00
2021-02-03 11:45:30 -05:00
2021-04-13 14:10:09 -07:00
2021-04-13 14:10:09 -07:00
2021-01-04 09:02:59 -08:00
2021-03-19 14:21:58 -07:00
2021-03-19 14:21:58 -07:00
2021-04-13 14:10:09 -07:00
2021-02-25 20:00:25 -05:00
2021-06-07 23:06:52 +02:00
2021-02-25 20:00:25 -05:00
2021-02-25 20:00:25 -05:00