Critical 9.8/10 vulnerability for this library
help wanted
According to [GitHub depandabot](https://github.com/vwbusguy/curses-examples/security/dependabot/3) this library now has a 9.8/10 vulnerability at the current version (5.101.0) as well as a [7.5/10 high](https://github.com/vwbusguy/curses-examples/security/dependabot/2).
Here are the CVEs:
[CVE-2019-15548](https://nvd.nist.gov/vuln/detail/CVE-2019-15548)
[CVE-2019-15547](https://nvd.nist.gov/vuln/detail/CVE-2019-15547)
Here's the corresponding [Rust Advisory](https://rustsec.org/advisories/RUSTSEC-2019-0006.html).
关闭于 2024-04-10 8 条评论