rustsec / rustsec/advisory-db

`malloc_buf` is unmaintained and unsound

Open
#1,635 0 comments 1 reaction 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
No language data
Stars
1.2k
Forks
544
Avg merge
1d 10h
Merged PRs (30d)
45

Description

Links:

Last actions:

  • Last commit on 2020-06-30
  • Last release on 2017-02-20

Unsoundness:

Dependents:

  • Direct dependents on crates.io: 3
  • Transitive dependents on github: 55,894
  • Used at run time in 2,243 crates (of which 2,190 optionally, 3 directly).
  • Used only as a dev dependency in 261 crates.

Downloads:

  • All time: 3,579,544
  • Recent: 537,970
  • Per month: 219,080

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Review the linked malloc_buf repository, crates.io page, lib.rs page, and unsoundness report first. Verify the unmaintained status and the reported unsoundness against the listed dependency and usage data; done is not defined by the issue text, so the required advisory change must be clarified before work begins.

Written by the indexing model from the issue text.

Assessment

Tech stack
rust
Domain
security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.