Add advisory for infisearch_common - #3106
Conversation
|
Please add the number of recent downloads on crates.io, as in the PR template, for all of your PRs. |
|
Thank you for checking and pointing this out. I have updated my recent PRs to include the recent downloads count according to the PR template. |
Also this bullet is there for a reason. Please discuss with the upstream maintainer(s) for each PR. |
|
Thank you for your guidance. We reported the issue upstream, but we have not received an explicit maintainer response confirming the issues, so I left the maintainer-confirmation checklist item unchecked. May I kindly ask whether this situation makes the advisory difficult to accept for RustSec, or whether there is any additional information I should provide to help with the review? |
|
We typically require approval from maintainers (that are active/reachable) before publishing a RustSec advisory. |
Affected crate(s)
Links to upstream issue(s) or PR(s)
Severity
This is submitted as an informational unsound advisory. The reported issue involves unchecked indexing in a safe method, which can lead to out-of-bounds access and undefined behavior.
Checklist
RUSTSEC-0000-0000as the IDdatefield is set to the public disclosure date