Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

office crate has soundness issue & unmaintained #742

Closed
JOE1994 opened this issue Feb 4, 2021 · 3 comments
Closed

office crate has soundness issue & unmaintained #742

JOE1994 opened this issue Feb 4, 2021 · 3 comments

Comments

@JOE1994
Copy link
Contributor

JOE1994 commented Feb 4, 2021

office crate has the exact same issue as tafia/calamine#199
in https://docs.rs/crate/office/0.8.1/source/src/cfb.rs (lines 175~184).

office crate's repository link leads to the github repo of the calamine crate.
office crate seems to be an older & unmaintained version of calamine.

@Shnatsel
Copy link
Member

Shnatsel commented Feb 4, 2021

Can you get clarification on this situation from office/calamine upstream? We're happy to carry advisories for both the vulnerability and the unmaintained status if there's no way to issue a new release of office.

@Qwaz
Copy link
Contributor

Qwaz commented Feb 4, 2021

The description of office crate on crates.io says (link):

See 'calamine' crate. Contact me for 'office' ownership

Having said that, I believe checking with the upstream is always encouraged.
cc @tafia, could you kindly confirm that the users of office crate are expected to use calamine instead?

@tafia
Copy link
Contributor

tafia commented Feb 4, 2021

I confirm that the office crate is NOT supported and has long since been replaced by calamine.

Shnatsel added a commit that referenced this issue Mar 3, 2021
Add unmaintained advisory for office crate. Fixes #742
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

4 participants