Bug#984665: [Pkg-rust-maintainers] Bug#984665: CVE-2021-25900

2021-03-09 Thread Peter Green
On 07/03/2021 02:30, plugwash-urgent wrote: my tentative conclusion is that the insert_many operation in rust-arrayvec does not seem to actually be used. While I can't find any applications that uses the broken function in rust-smallvec (saying arrayvec above was a brainfart), I still think we

Bug#984665: [Pkg-rust-maintainers] Bug#984665: CVE-2021-25900

2021-03-06 Thread plugwash-urgent
I started looking into this bug and trying to gauge it's impact. In particular what if-any applications in Debian actually use the broken code. First I tried to use codesearch to search for insert_many but I got way too many false-positives. So I tried a different approach. I did however