RUSTSEC-2020-0071: Potential segfault in the time crate
Nadie ha tomado este issue todavía.
Evaluación
- Dificultad
- 2/5
- Tiempo estimado
- 1-3 horas
- Aptitud para principiantes
- 25/100
Línea de trabajo
Comienza con la información de dependencias de Rust en este aviso e inspecciona las declaraciones de dependencias del repositorio para la crate time. Usa cargo update como se describe, asegúrate de que la dependencia se resuelva a una versión parcheada no afectada y verifica que no quede ninguna versión vulnerable de time en el árbol de dependencias.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
Potential segfault in the time crate
| Details | |
|---|---|
| Package | time |
| Version | 0.1.44 |
| URL | https://github.com/time-rs/time/issues/293 |
| Date | 2020-11-18 |
| Patched versions | >=0.2.23 |
| Unaffected versions | =0.2.0,=0.2.1,=0.2.2,=0.2.3,=0.2.4,=0.2.5,=0.2.6 |
Impact
Unix-like operating systems may segfault due to dereferencing a dangling pointer in specific circumstances. This requires an environment variable to be set in a different thread than the affected functions. This may occur without the user's knowledge, notably in a third-party library.
The affected functions from time 0.2.7 through 0.2.22 are:
time::UtcOffset::local_offset_attime::UtcOffset::try_local_offset_attime::UtcOffset::current_local_offsettime::UtcOffset::try_current_local_offsettime::OffsetDateTime::now_localtime::OffsetDateTime::try_now_local
The affected functions in time 0.1 (all versions) are:
atat_utcnow
Non-Unix targets (including Windows and wasm) are unaffected.
Patches
Pending a proper fix, the internal method that determines the local offset has been modified to always return None on the affected operating systems. This has the effect of returning an Err on the try_* methods and UTC on the non-try_* methods.
Users and library authors with time in their dependency tree should perform cargo update, which will pull in the updated, unaffected code.
Users of time 0.1 do not have a patch and should upgrade to an unaffected version: time 0.2.23 or greater or the 0.3 series.
Workarounds
No workarounds are known.
See advisory page for additional details.
- Lenguaje dominante
- Python
- Estrellas
- 9
- Forks
- 3
- Merge medio
- 14 h 45 min
- PR fusionados (30 d)
- 7
Preparar el entorno
- Sin Dockerfile ni archivo de Docker Compose
- Tiene una plantilla de pull request
- Sin guía de contribución
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de stackabletech/listener-operator
-
ListenerClass CRD restructureQuizá libre de nuevo @NickLarsenNZ la tomó hace 410 días y no hay ningún pull request abierto. Abierto
stackabletech/listener-operator#330 · 5 comentarios · 1 reacción · 1 asignado ·
-
OpenShift Route backendPosiblemente ocupada @marc-merino la tomó hace 3 días. Abierto
Dificultad 4/5 3-5 días Aptitud para principiantes 35/100
-
customer-request
Dificultad 4/5 3-5 días Aptitud para principiantes 35/100
stackabletech/listener-operator#302 · 1 comentario ·
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 20/100
-
Rename `listeners.stackable.tech/listener-class` PVC annotation to `listeners.stackable.tech/class`Abierto
Dificultad 3/5 1-2 días Aptitud para principiantes 43/100
stackabletech/listener-operator#271 · 1 comentario ·
Todos los issues de stackabletech/listener-operator
Issues similares
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 82/100
LearningCircuit/local-deep-research#7206 ·
Los mantenedores suelen responder en 1 día
-
[TASK] Document technology stackAbierto
Dificultad 2/5 1-3 horas Aptitud para principiantes 68/100
chingu-voyages/V62-tier3-team-33#285 ·
Los mantenedores suelen responder en 1 día
-
Proxy drops log notifications from backends that don't send FastMCP's msg/extra dictPosiblemente ocupada @asasemahmed la tomó hoy. Abiertobug server
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 82/100
Los mantenedores suelen responder en 1 día
-
[Bug]: Bedrock request metadata forwarding does not work for /embeddingsPosiblemente ocupada Un pull request vinculado a esta issue está abierto o ya se fusionó. Abiertobug llm translation
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
Los mantenedores suelen responder en 1 día