This repository was archived by the owner on Feb 16, 2024. It is now read-only.
chore(deps): update rust crate openssl to v0.10.60 [security]#295
Open
stackable-bot wants to merge 1 commit intomainfrom
Open
chore(deps): update rust crate openssl to v0.10.60 [security]#295stackable-bot wants to merge 1 commit intomainfrom
stackable-bot wants to merge 1 commit intomainfrom
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
0.10.45->0.10.60GitHub Vulnerability Alerts
GHSA-9qwg-crg9-m2vc
SubjectAlternativeNameandExtendedKeyUsagearguments were parsed using the OpenSSL functionX509V3_EXT_nconf. This function parses all input using an OpenSSL mini-language which can perform arbitrary file reads.Thanks to David Benjamin (Google) for reporting this issue.
GHSA-6hcf-g6gr-hhcr
These functions would crash when the context argument was None with certain extension types.
Thanks to David Benjamin (Google) for reporting this issue.
GHSA-3gxf-9r58-2ghg
OpenSSL has a
modifiedbit that it can set on onX509_NAMEobjects. If this bit is set then the object is not thread-safe even when it appears the code is not modifying the value.Thanks to David Benjamin (Google) for reporting this issue.
GHSA-xcf7-rvmh-g6q4
When this function was passed an empty string,
opensslwould attempt to callstrlenon it, reading arbitrary memory until it reached a NUL byte.GHSA-xphf-cx8h-7q9g
This function returned a reference into an OpenSSL datastructure, but there was no way to ensure OpenSSL would not mutate the datastructure behind one's back.
Use of this function should be replaced with
X509StoreRef::all_certificates.Release Notes
sfackler/rust-openssl (openssl)
v0.10.60Compare Source
What's Changed
update_uncheckedtosymm::Crypterby @alex in https://github.com/sfackler/rust-openssl/pull/2100X509StoreRef::objects, it is unsound by @alex in https://github.com/sfackler/rust-openssl/pull/2099Full Changelog: rust-openssl/rust-openssl@openssl-v0.10.59...openssl-v0.10.60
v0.10.59Compare Source
What's Changed
New Contributors
Full Changelog: rust-openssl/rust-openssl@openssl-v0.10.58...openssl-v0.10.59
v0.10.58Compare Source
What's Changed
New Contributors
Full Changelog: rust-openssl/rust-openssl@openssl-v0.10.57...openssl-v0.10.58
v0.10.57Compare Source
What's Changed
New Contributors
Full Changelog: rust-openssl/rust-openssl@openssl-v0.10.56...openssl-v0.10.57
v0.10.56: openssl v0.10.56Compare Source
v0.10.55Compare Source
What's Changed
New Contributors
Full Changelog: rust-openssl/rust-openssl@openssl-v0.10.54...openssl-v0.10.55
v0.10.54Compare Source
What's Changed
Full Changelog: rust-openssl/rust-openssl@openssl-v0.10.53...openssl-v0.10.54
v0.10.53Compare Source
What's Changed
DSAPrivateKeyby @alex in https://github.com/sfackler/rust-openssl/pull/1939New Contributors
Full Changelog: rust-openssl/rust-openssl@openssl-v0.10.52...openssl-v0.10.53
v0.10.52Compare Source
What's Changed
New Contributors
Full Changelog: rust-openssl/rust-openssl@openssl-v0.10.51...openssl-v0.10.52
v0.10.51Compare Source
What's Changed
New Contributors
Full Changelog: rust-openssl/rust-openssl@openssl-v0.10.50...openssl-v0.10.51
v0.10.50: openssl v0.10.50Compare Source
v0.10.49: openssl v0.10.49Compare Source
v0.10.48: openssl v0.10.48Compare Source
What's Changed
New Contributors
Full Changelog: rust-openssl/rust-openssl@openssl-v0.10.47...openssl-v0.10.48
v0.10.47: openssl v0.10.47Compare Source
v0.10.46: openssl v0.10.46Compare Source
Configuration
📅 Schedule: Branch creation - "" in timezone Europe/Berlin, Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Renovate Bot.