Skip to content

[GHSA-cqpr-pcm7-m3jc] Potential segfault in localtime_r invocations #427

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Closed

Conversation

LunaBorowska
Copy link

Updates

  • Affected products
  • Description
  • References

@github-actions github-actions bot changed the base branch from main to xfix/advisory-improvement-427 June 22, 2022 20:03
@LunaBorowska
Copy link
Author

LunaBorowska commented Jun 22, 2022

By the way, I would like to note that RustSec withdrawn this vulnerability (https://rustsec.org/advisories/RUSTSEC-2020-0159.html). Assigning CNA for this vulnerability is GitHub, so figured I would tell you in case you want to want to dispute this vulnerability or something. The reason being that RustSec doesn't consider using getenv to be a vulnerability anymore, but rather using std::env::set_env with multiple threads (see rustsec/advisory-db#1190).

@LunaBorowska
Copy link
Author

Oops, I got confused by RUSTSEC. CVE-2020-26235 is a vulnerability for time crate. That said, the vulnerability was withdrawn, see https://rustsec.org/advisories/RUSTSEC-2020-0159.html.

@github-actions github-actions bot deleted the xfix-GHSA-cqpr-pcm7-m3jc branch June 22, 2022 20:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant