Логотип exploitDog
bind:"CVE-2023-38497"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2023-38497"

Количество 13

Количество 13

ubuntu логотип

CVE-2023-38497

больше 2 лет назад

Cargo downloads the Rust project’s dependencies and compiles the project. Cargo prior to version 0.72.2, bundled with Rust prior to version 1.71.1, did not respect the umask when extracting crate archives on UNIX-like systems. If the user downloaded a crate containing files writeable by any local user, another local user could exploit this to change the source code compiled and executed by the current user. To prevent existing cached extractions from being exploitable, the Cargo binary version 0.72.2 included in Rust 1.71.1 or later will purge caches generated by older Cargo versions automatically. As a workaround, configure one's system to prevent other local users from accessing the Cargo directory, usually located in `~/.cargo`.

CVSS3: 7.9
EPSS: Низкий
redhat логотип

CVE-2023-38497

больше 2 лет назад

Cargo downloads the Rust project’s dependencies and compiles the project. Cargo prior to version 0.72.2, bundled with Rust prior to version 1.71.1, did not respect the umask when extracting crate archives on UNIX-like systems. If the user downloaded a crate containing files writeable by any local user, another local user could exploit this to change the source code compiled and executed by the current user. To prevent existing cached extractions from being exploitable, the Cargo binary version 0.72.2 included in Rust 1.71.1 or later will purge caches generated by older Cargo versions automatically. As a workaround, configure one's system to prevent other local users from accessing the Cargo directory, usually located in `~/.cargo`.

CVSS3: 6.7
EPSS: Низкий
nvd логотип

CVE-2023-38497

больше 2 лет назад

Cargo downloads the Rust project’s dependencies and compiles the project. Cargo prior to version 0.72.2, bundled with Rust prior to version 1.71.1, did not respect the umask when extracting crate archives on UNIX-like systems. If the user downloaded a crate containing files writeable by any local user, another local user could exploit this to change the source code compiled and executed by the current user. To prevent existing cached extractions from being exploitable, the Cargo binary version 0.72.2 included in Rust 1.71.1 or later will purge caches generated by older Cargo versions automatically. As a workaround, configure one's system to prevent other local users from accessing the Cargo directory, usually located in `~/.cargo`.

CVSS3: 7.9
EPSS: Низкий
msrc логотип

CVE-2023-38497

больше 2 лет назад

Cargo not respecting umask when extracting crate archives

CVSS3: 7.3
EPSS: Низкий
debian логотип

CVE-2023-38497

больше 2 лет назад

Cargo downloads the Rust project\u2019s dependencies and compiles the ...

CVSS3: 7.9
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:3251-1

больше 2 лет назад

Security update for rust1.71

EPSS: Низкий
rocky логотип

RLSA-2023:4635

больше 2 лет назад

Important: rust-toolset:rhel8 security update

EPSS: Низкий
rocky логотип

RLSA-2023:4634

больше 2 лет назад

Important: rust security update

EPSS: Низкий
github логотип

GHSA-j3xp-wfr4-hx87

больше 2 лет назад

Cargo not respecting umask when extracting crate archives

CVSS3: 7.9
EPSS: Низкий
oracle-oval логотип

ELSA-2023-4635

больше 2 лет назад

ELSA-2023-4635: rust-toolset:ol8 security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2023-4634

больше 2 лет назад

ELSA-2023-4634: rust security update (IMPORTANT)

EPSS: Низкий
fstec логотип

BDU:2024-05823

больше 2 лет назад

Уязвимость менеджера пакетов Cargo языка программирования Rust, позволяющая нарушителю выполнить произвольный код

CVSS3: 7.3
EPSS: Низкий
redos логотип

ROS-20240729-09

больше 1 года назад

Уязвимость rust

CVSS3: 7.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2023-38497

Cargo downloads the Rust project’s dependencies and compiles the project. Cargo prior to version 0.72.2, bundled with Rust prior to version 1.71.1, did not respect the umask when extracting crate archives on UNIX-like systems. If the user downloaded a crate containing files writeable by any local user, another local user could exploit this to change the source code compiled and executed by the current user. To prevent existing cached extractions from being exploitable, the Cargo binary version 0.72.2 included in Rust 1.71.1 or later will purge caches generated by older Cargo versions automatically. As a workaround, configure one's system to prevent other local users from accessing the Cargo directory, usually located in `~/.cargo`.

CVSS3: 7.9
6%
Низкий
больше 2 лет назад
redhat логотип
CVE-2023-38497

Cargo downloads the Rust project’s dependencies and compiles the project. Cargo prior to version 0.72.2, bundled with Rust prior to version 1.71.1, did not respect the umask when extracting crate archives on UNIX-like systems. If the user downloaded a crate containing files writeable by any local user, another local user could exploit this to change the source code compiled and executed by the current user. To prevent existing cached extractions from being exploitable, the Cargo binary version 0.72.2 included in Rust 1.71.1 or later will purge caches generated by older Cargo versions automatically. As a workaround, configure one's system to prevent other local users from accessing the Cargo directory, usually located in `~/.cargo`.

CVSS3: 6.7
6%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-38497

Cargo downloads the Rust project’s dependencies and compiles the project. Cargo prior to version 0.72.2, bundled with Rust prior to version 1.71.1, did not respect the umask when extracting crate archives on UNIX-like systems. If the user downloaded a crate containing files writeable by any local user, another local user could exploit this to change the source code compiled and executed by the current user. To prevent existing cached extractions from being exploitable, the Cargo binary version 0.72.2 included in Rust 1.71.1 or later will purge caches generated by older Cargo versions automatically. As a workaround, configure one's system to prevent other local users from accessing the Cargo directory, usually located in `~/.cargo`.

CVSS3: 7.9
6%
Низкий
больше 2 лет назад
msrc логотип
CVE-2023-38497

Cargo not respecting umask when extracting crate archives

CVSS3: 7.3
6%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-38497

Cargo downloads the Rust project\u2019s dependencies and compiles the ...

CVSS3: 7.9
6%
Низкий
больше 2 лет назад
suse-cvrf логотип
SUSE-SU-2023:3251-1

Security update for rust1.71

6%
Низкий
больше 2 лет назад
rocky логотип
RLSA-2023:4635

Important: rust-toolset:rhel8 security update

6%
Низкий
больше 2 лет назад
rocky логотип
RLSA-2023:4634

Important: rust security update

6%
Низкий
больше 2 лет назад
github логотип
GHSA-j3xp-wfr4-hx87

Cargo not respecting umask when extracting crate archives

CVSS3: 7.9
6%
Низкий
больше 2 лет назад
oracle-oval логотип
ELSA-2023-4635

ELSA-2023-4635: rust-toolset:ol8 security update (IMPORTANT)

больше 2 лет назад
oracle-oval логотип
ELSA-2023-4634

ELSA-2023-4634: rust security update (IMPORTANT)

больше 2 лет назад
fstec логотип
BDU:2024-05823

Уязвимость менеджера пакетов Cargo языка программирования Rust, позволяющая нарушителю выполнить произвольный код

CVSS3: 7.3
6%
Низкий
больше 2 лет назад
redos логотип
ROS-20240729-09

Уязвимость rust

CVSS3: 7.3
6%
Низкий
больше 1 года назад

Уязвимостей на страницу