Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-RU-2019:0386-1

Опубликовано: 14 фев. 2019
Источник: suse-cvrf

Описание

Security update for rust

Rust was updated to version 1.31.1.

Список пакетов

SUSE Linux Enterprise Module for Development Tools 15
cargo-1.31.1-3.9.2
clippy-1.31.1-3.9.2
rls-1.31.1-3.9.2
rust-1.31.1-3.9.2
rust-analysis-1.31.1-3.9.2
rust-gdb-1.31.1-3.9.2
rust-src-1.31.1-3.9.2
rust-std-static-1.31.1-3.9.2
rustfmt-1.31.1-3.9.2

Описание

The Rust Programming Language rustdoc version Between 0.8 and 1.27.0 contains a CWE-427: Uncontrolled Search Path Element vulnerability in rustdoc plugins that can result in local code execution as a different user. This attack appear to be exploitable via using the --plugin flag without the --plugin-path flag. This vulnerability appears to have been fixed in 1.27.1.


Затронутые продукты
SUSE Linux Enterprise Module for Development Tools 15:cargo-1.31.1-3.9.2
SUSE Linux Enterprise Module for Development Tools 15:clippy-1.31.1-3.9.2
SUSE Linux Enterprise Module for Development Tools 15:rls-1.31.1-3.9.2
SUSE Linux Enterprise Module for Development Tools 15:rust-1.31.1-3.9.2

Ссылки