RUSTSEC-2025-0010

Source
https://rustsec.org/advisories/RUSTSEC-2025-0010
Import Source
https://github.com/rustsec/advisory-db/blob/osv/crates/RUSTSEC-2025-0010.json
JSON Data
https://api.osv.dev/v1/vulns/RUSTSEC-2025-0010
Published
2025-03-05T12:00:00Z
Modified
2025-03-07T15:46:47Z
Summary
Versions of *ring* prior to 0.17 are unmaintained.
Details

ring 0.16.20 was released over 4 years ago and isn't maintained, tested, etc.

Additionally, the project's general policy is to only patch the latest release, which is 0.17.12 now. It will be difficult for anybody to backport future fixes to versions earlier than 0.17.10 due to license changes.

Database specific
{
    "license": "CC0-1.0"
}
References

Affected packages

crates.io / ring

Package

Affected ranges

Type
SEMVER
Events
Introduced
0.0.0-0
Fixed
0.17.0

Ecosystem specific

{
    "affected_functions": null,
    "affects": {
        "os": [],
        "functions": [],
        "arch": []
    }
}

Database specific

{
    "cvss": null,
    "informational": "unmaintained",
    "categories": []
}