{
  "schema_version": "1.7.0",
  "id": "MGASA-2021-0251",
  "published": "2021-06-13T21:32:39Z",
  "modified": "2021-06-13T20:17:14Z",
  "summary": "Updated rust packages fix security vulnerabilities",
  "details": "This Rust update to version 1.52.1 includes security fixes for CVE-2020-36323,\nCVE-2021-28876, CVE-2021-28878, CVE-2021-28879, and CVE-2021-31162.\nThese are memory safety bugs in the Rust standard library. Because it is\nstatically linked, affected applications will need to be rebuilt to benefit\nfrom the fixes. The actual security implications will depend on how these APIs\nare used in each particular case.\n\nThis update also provides new features and bugfixes included in Rust since\nthe previously packaged version 1.49.0. See the referenced release notes for\ndetails.\n\nThe mozjs78 package is also updated from version 78.7.0 to 78.11.0 (ESR).\n",
  "upstream": [
    "CVE-2020-36323",
    "CVE-2021-28876",
    "CVE-2021-28878",
    "CVE-2021-28879",
    "CVE-2021-31162"
  ],
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://advisories.mageia.org/MGASA-2021-0251.html"
    },
    {
      "type": "REPORT",
      "url": "https://bugs.mageia.org/show_bug.cgi?id=29033"
    },
    {
      "type": "WEB",
      "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/CZ337CM4GFJLRDFVQCGC7J25V65JXOG5/"
    },
    {
      "type": "WEB",
      "url": "https://blog.rust-lang.org/2021/02/11/Rust-1.50.0.html"
    },
    {
      "type": "WEB",
      "url": "https://blog.rust-lang.org/2021/03/25/Rust-1.51.0.html"
    },
    {
      "type": "WEB",
      "url": "https://blog.rust-lang.org/2021/05/06/Rust-1.52.0.html"
    },
    {
      "type": "WEB",
      "url": "https://blog.rust-lang.org/2021/05/10/Rust-1.52.1.html"
    }
  ],
  "affected": [
    {
      "package": {
        "ecosystem": "Mageia:8",
        "name": "rust",
        "purl": "pkg:rpm/mageia/rust?arch=source&distro=mageia-8"
      },
      "ranges": [
        {
          "type": "ECOSYSTEM",
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "1.52.1-1.mga8"
            }
          ]
        }
      ],
      "ecosystem_specific": {
        "section": "core"
      }
    },
    {
      "package": {
        "ecosystem": "Mageia:8",
        "name": "alacritty",
        "purl": "pkg:rpm/mageia/alacritty?arch=source&distro=mageia-8"
      },
      "ranges": [
        {
          "type": "ECOSYSTEM",
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "0.7.1-1.1.mga8"
            }
          ]
        }
      ],
      "ecosystem_specific": {
        "section": "core"
      }
    },
    {
      "package": {
        "ecosystem": "Mageia:8",
        "name": "cargo-c",
        "purl": "pkg:rpm/mageia/cargo-c?arch=source&distro=mageia-8"
      },
      "ranges": [
        {
          "type": "ECOSYSTEM",
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "0.7.0-1.1.mga8"
            }
          ]
        }
      ],
      "ecosystem_specific": {
        "section": "core"
      }
    },
    {
      "package": {
        "ecosystem": "Mageia:8",
        "name": "dust",
        "purl": "pkg:rpm/mageia/dust?arch=source&distro=mageia-8"
      },
      "ranges": [
        {
          "type": "ECOSYSTEM",
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "0.5.1-1.1.mga8"
            }
          ]
        }
      ],
      "ecosystem_specific": {
        "section": "core"
      }
    },
    {
      "package": {
        "ecosystem": "Mageia:8",
        "name": "librsvg",
        "purl": "pkg:rpm/mageia/librsvg?arch=source&distro=mageia-8"
      },
      "ranges": [
        {
          "type": "ECOSYSTEM",
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "2.50.3-1.1.mga8"
            }
          ]
        }
      ],
      "ecosystem_specific": {
        "section": "core"
      }
    },
    {
      "package": {
        "ecosystem": "Mageia:8",
        "name": "mozjs68",
        "purl": "pkg:rpm/mageia/mozjs68?arch=source&distro=mageia-8"
      },
      "ranges": [
        {
          "type": "ECOSYSTEM",
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "68.11.0-1.1.mga8"
            }
          ]
        }
      ],
      "ecosystem_specific": {
        "section": "core"
      }
    },
    {
      "package": {
        "ecosystem": "Mageia:8",
        "name": "mozjs78",
        "purl": "pkg:rpm/mageia/mozjs78?arch=source&distro=mageia-8"
      },
      "ranges": [
        {
          "type": "ECOSYSTEM",
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "78.11.0-1.mga8"
            }
          ]
        }
      ],
      "ecosystem_specific": {
        "section": "core"
      }
    },
    {
      "package": {
        "ecosystem": "Mageia:8",
        "name": "neovim-gtk",
        "purl": "pkg:rpm/mageia/neovim-gtk?arch=source&distro=mageia-8"
      },
      "ranges": [
        {
          "type": "ECOSYSTEM",
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "0.2.0-0.git20190512.2.1.mga8"
            }
          ]
        }
      ],
      "ecosystem_specific": {
        "section": "core"
      }
    },
    {
      "package": {
        "ecosystem": "Mageia:8",
        "name": "ripgrep",
        "purl": "pkg:rpm/mageia/ripgrep?arch=source&distro=mageia-8"
      },
      "ranges": [
        {
          "type": "ECOSYSTEM",
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "12.1.1-1.1.mga8"
            }
          ]
        }
      ],
      "ecosystem_specific": {
        "section": "core"
      }
    }
  ],
  "credits": [
    {
      "name": "Mageia",
      "type": "COORDINATOR",
      "contact": [
        "https://wiki.mageia.org/en/Packages_Security_Team"
      ]
    }
  ]
}
