Bug#1068418: rust-openssl: CVE-2024-3296

2025-04-15 Thread Peter Green
Tags 1068418 +wontfix After a bunch of back and forth the upstream maintainer of this crate has stated. The goal of this crate is to implement direct, memory safe bindings to OpenSSL APIs. Some of those APIs are poorly designed, but that is frankly OpenSSL's problem, not my problem.

Bug#1068418: rust-openssl: CVE-2024-3296

2024-04-04 Thread Salvatore Bonaccorso
Source: rust-openssl Version: 0.10.64-1 Severity: important Tags: security upstream Forwarded: https://github.com/sfackler/rust-openssl/issues/2171 X-Debbugs-Cc: car...@debian.org, Debian Security Team Hi, The following vulnerability was published for rust-openssl. CVE-2024-3296[0]: | A timing-