RustSec

148 posts

RustSec

RustSec

@RustSec

Security advisory database for Rust crates published through https://t.co/NctFWNHsjG. A project of the @rustsecurecode working group.

Katılım Ocak 2017
17 Takip Edilen2.4K Takipçiler
Sabitlenmiş Tweet
RustSec
RustSec@RustSec·
Growth in the @RustSec security advisory database year-over-year throughout its 6-year history
RustSec tweet media
English
1
3
17
0
RustSec retweetledi
GitHub
GitHub@github·
Rust is the fastest growing language on GitHub, and GitHub’s supply chain security features now help keep your Rust projects secure 🔒 github.co/3tiGH9E
English
5
92
301
0
RustSec retweetledi
Rust Language
Rust Language@rustlang·
The regex crate is vulnerable to denial of service attacks when parsing untrusted regexes (CVE-2022-24713). We released version 1.5.5, fixing the issue. Read the advisory: blog.rust-lang.org/2022/03/08/cve…
English
2
71
232
0
RustSec retweetledi
Rust Language
Rust Language@rustlang·
The std::fs::remove_dir_all function in the Rust standard library is vulnerable to a race condition (CVE-2022-21658). We will release Rust 1.58.1 with the fix later today. Read the advisory: blog.rust-lang.org/2022/01/20/cve…
English
0
86
320
0
RustSec
RustSec@RustSec·
Growth in the @RustSec security advisory database year-over-year throughout its 6-year history
RustSec tweet media
English
1
3
17
0
RustSec
RustSec@RustSec·
@Erstejahre From the @RustSec side, you can file an advisory for the affected release so cargo-audit users will see it. If the crate can be reclaimed, the malicious release should be yanked. Beyond that there isn’t a process I’m aware of, but I can ask the crates.io team!
English
2
0
3
0
Firstyear
Firstyear@Erstejahre·
@RustSec Theoretical question for you - If a crate was hijacked and had a cryptominer or other malicious code added, is there an established process to have that removed to prevent infections to consumers of crates.io ?
English
1
0
0
0
Ada Worcester 🏳️‍⚧️
@RustSec Isn't the problem here that std::env::set_env, which wraps C setenv(), is incorrectly marked as safe? After all, in C-land, calling setenv() while any other thread is accessing the environment (including potentially arbitrary other C functions) is undefined behavior.
English
2
0
4
0
RustSec
RustSec@RustSec·
Heads up Rustsceans! You might have recently gotten a security vulnerability notification for RUSTSEC-2020-0071: a potential segfault impacting `time` v0.1 (cont’d) rustsec.org/advisories/RUS…
English
1
4
24
0
RustSec
RustSec@RustSec·
The rustsec.org web site now features severity information for each security advisory
RustSec tweet mediaRustSec tweet media
English
0
4
16
0
RustSec
RustSec@RustSec·
@hdevalence In programs where certain environment variables are modified from different threads, it can result in memory corruption. This has manifested as programs segfaulting.
English
0
0
2
0
RustSec
RustSec@RustSec·
@jonasbb92 Probably. We’re discussing it on the #wg-secure-code Zulip channel.
English
1
0
3
0
RustSec
RustSec@RustSec·
Unfortunately we don’t have clear guidance for what to do. It impacts several major ecosystem crates including `chrono`. For the latest information, see the upstream issue on `time`: github.com/time-rs/time/i…
English
2
0
26
0
RustSec
RustSec@RustSec·
This isn’t a false positive, but rather a case where the advisory has been updated to include earlier versions of the `time` crate. Unfortunately the fix is only in `time` v0.2, and it’s unclear if it can be backported to v0.1 due to API constraints.
English
1
0
11
0
RustSec retweetledi
Kate Catlin
Kate Catlin@Kate_Catlin·
My team's first release since I joined GitHub is out today, and my first GitHub blog is live! Thanks so much to the @RustSec community for collaborating to bring curated Rust security advisories to the GitHub Advisory Database! github.blog/2021-09-23-git…
English
0
16
82
0
RustSec
RustSec@RustSec·
@KodrAus (we have withdrawn some unmaintained crate advisories, but that was because new maintainers stepped up which is what we’re trying to encourage!)
English
0
0
1
0
RustSec
RustSec@RustSec·
@KodrAus As you are seeing, we perform due diligence before publishing unmaintained crate advisories. Agreed we could use a more formal policy, but so far in the course of several years we have not received any complaints about maintained crates being marked unmaintained.
English
1
0
1
0
RustSec
RustSec@RustSec·
@bodil question about the im/im-rc crates: we have a request to mark them as unmaintained in the RustSec Advisory Database: github.com/RustSec/adviso… Is that ok? If you have any objections whatsoever we'll close the PR.
English
1
0
1
0