Skip to content

Advisory: sodiumoxide degenerate public keys#4

Merged
tarcieri merged 1 commit into
masterfrom
sodiumoxide-degenerate-public-keys
Feb 26, 2017
Merged

Advisory: sodiumoxide degenerate public keys#4
tarcieri merged 1 commit into
masterfrom
sodiumoxide-degenerate-public-keys

Conversation

@tarcieri
Copy link
Copy Markdown
Member

@tarcieri tarcieri commented Feb 25, 2017

Fixed in sodiumoxide 0.0.14 (cc @dnaq)

See: https://github.com/dnaq/sodiumoxide/issues/154


This commit also serves as a sort of archetype for filing future security advisories.

It proposes a RUSTSEC-YYYY-NNNN format for identifying advisories. Ideally we'd use Distributed Weakness Filing for this purpose, but I've been having trouble getting ahold of the DWF maintainer to move forward on that (cc @kurtseifried)

However, we can adopt the RUSTSEC-... scheme for now, then refile vulnerabilities under DWF if and when we get a block assigned (RubySec, as an example, has had to refile vulnerabilities this way several times)

@tarcieri tarcieri force-pushed the sodiumoxide-degenerate-public-keys branch from 5b8a684 to 2d75a22 Compare February 26, 2017 00:07
@tarcieri tarcieri force-pushed the sodiumoxide-degenerate-public-keys branch from 2d75a22 to 1a18a42 Compare February 26, 2017 00:29
@tarcieri tarcieri merged commit 0aeb6b9 into master Feb 26, 2017
@tarcieri tarcieri deleted the sodiumoxide-degenerate-public-keys branch February 26, 2017 00:43
tarcieri added a commit that referenced this pull request Feb 26, 2017
@tarcieri
Copy link
Copy Markdown
Member Author

This has been filed as RUSTSEC-2017-0001

@tarcieri tarcieri added advisory security advisory PRs cryptographic failure breakage in cryptographic confidentiality or authenticity labels Aug 25, 2018
berkant-koc pushed a commit to berkant-koc/advisory-db that referenced this pull request May 17, 2026
Maintainer @spearman published v0.3.0 on 2026-05-16 with the fix plus
regression test race_disconnect_does_not_corrupt_sender_or_abort
(commit 2714da2), accepted GHSA-6m57-8r3p-pqx6, and closed upstream
issue rustsec#4. All prior versions (0.2.0, 0.1.x) are yanked on crates.io.

- patched = [">= 0.3.0"]
- aliases = ["GHSA-6m57-8r3p-pqx6"]
- url = spearman/unbounded-spsc#4
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

advisory security advisory PRs cryptographic failure breakage in cryptographic confidentiality or authenticity

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant