advisory-db
advisory-db copied to clipboard
hexchat (all versions) is unsound (use-after-free)
The hexchat
crate has register_command
and deregister_command
functions. When used together, they can cause an use-after-free. This seems to be the case with most if not all of the callback-related functions.
Additionally, the crate seems to be no longer maintained.
Linking to relevant issue, https://github.com/pie-flavor/hexchat-rs/issues/1
Would be keen to get this ticket and https://github.com/rustsec/advisory-db/issues/913 dealt with
I've pinged the maintainer and asked if the crate should be used here - https://github.com/pie-flavor/hexchat-rs/issues/2
@SoniEx2 would you like to send informational = "unmaintained" PR and describe these soundness issues alongside
It should deal with both this and #913 but we could just flag one unmaintained that contains the soundness issues
Cheers