brave / adblock-rust-ffi

An FFI crate to expose functionality from brave/adblock-rust
Mozilla Public License 2.0
47 stars 16 forks source link

Fix smallvec 1.4.0 vulnerability #28

Closed mkarolin closed 3 years ago

mkarolin commented 3 years ago
 
Crate:         smallvec
 Version:       1.4.0
 Title:         Buffer overflow in SmallVec::insert_many
 Date:          2021-01-08
 ID:            RUSTSEC-2021-0003
 URL:           https://rustsec.org/advisories/RUSTSEC-2021-0003
 Solution:      Upgrade to >=0.6.14, <1.0.0 OR >=1.6.1
 Dependency tree: 
 smallvec 1.4.0
 └── unicode-normalization 0.1.12
     └── idna 0.2.0
         ├── url 2.1.1
         │   └── adblock 0.3.4
         │       └── adblock-ffi 0.1.0
         └── adblock 0.3.4

 Crate:         smallvec
 Version:       1.4.0
 Warning:       yanked

 error: 1 vulnerability found!