Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add advisory for pkcs11 #1280

Closed
5225225 opened this issue Jul 8, 2022 · 6 comments
Closed

Add advisory for pkcs11 #1280

5225225 opened this issue Jul 8, 2022 · 6 comments

Comments

@5225225
Copy link
Contributor

5225225 commented Jul 8, 2022

The crate hasn't been touched in 2 years, and seems to have a fair few possibly security-related open issues.

mheese/rust-pkcs11#55
mheese/rust-pkcs11#54
mheese/rust-pkcs11#49
mheese/rust-pkcs11#53

I can't quite work out what to mark as the advisory, and don't know the crate well enough to explain these issues.

@tarcieri
Copy link
Member

It might qualify as unmaintained. See our policy/process here: https://github.com/rustsec/advisory-db/blob/main/HOWTO_UNMAINTAINED.md

@ionut-arm
Copy link
Contributor

I've raised an issue on the repo, we can wait and see if we get a reply :)

@5225225
Copy link
Contributor Author

5225225 commented Jul 20, 2022

If you're more familiar with the memory safety issues @ionut-arm maybe you could write / help me write the advisory (by listing/explaining the distinct issues with it so I can list em)?

Since "this is unmaintained" isn't the only issue with it.

@ionut-arm
Copy link
Contributor

ionut-arm commented Jul 20, 2022

Happy to create a draft PR with the advisory just for the safety issues for now, and I can add the "unmaintained" bit later on, when I can link to that issue.

Edit: Or alternatively I can write up a short description/list here for you to cover?

@5225225
Copy link
Contributor Author

5225225 commented Jul 20, 2022

I think a draft PR that you can tag me in to look over would be fine (so other people can look over it too). I'm AFK at the moment but can check over it in 2ish hours.

@5225225
Copy link
Contributor Author

5225225 commented Jul 28, 2022

Done in #1282

@5225225 5225225 closed this as completed Jul 28, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants