Several memory safety issues have been uncovered in an audit of rusqlite.
See https://github.com/rusqlite/rusqlite/releases/tag/0.23.0 for a complete list.
townhopper_cli 0.1.1
This project might be open to known security vulnerabilities, which can be prevented by tightening the version range of affected dependencies. Find detailed information at the bottom.
townhopper_cli
(10 total, 5 outdated, 2 possibly insecure)
Crate | Required | Latest | Status |
---|---|---|---|
chrono ⚠️ | ^0.4 | 0.4.37 | maybe insecure |
chrono-systemd-time | ^0.1 | 0.3.0 | out of date |
clap | ^2.32 | 4.5.4 | out of date |
config | ^0.9 | 0.14.0 | out of date |
lazy_static | ^1.2 | 1.4.0 | up to date |
log | ^0.4 | 0.4.21 | up to date |
rusqlite ⚠️ | ^0.19 | 0.31.0 | out of date |
stderrlog | ^0.4 | 0.6.0 | out of date |
townhopper | =0.1.1 | 0.1.1 | up to date |
xdg | ^2.2 | 2.5.2 | up to date |
rusqlite
: Various memory safety issuesSeveral memory safety issues have been uncovered in an audit of rusqlite.
See https://github.com/rusqlite/rusqlite/releases/tag/0.23.0 for a complete list.
chrono
: Potential segfault in `localtime_r` invocationsUnix-like operating systems may segfault due to dereferencing a dangling pointer in specific circumstances. This requires an environment variable to be set in a different thread than the affected functions. This may occur without the user's knowledge, notably in a third-party library.
No workarounds are known.