Логотип exploitDog
bind:"GHSA-j3xp-wfr4-hx87" OR bind:"CVE-2023-38497"
Консоль
Логотип exploitDog

exploitDog

bind:"GHSA-j3xp-wfr4-hx87" OR bind:"CVE-2023-38497"

Количество 11

Количество 11

github логотип

GHSA-j3xp-wfr4-hx87

около 2 лет назад

Cargo not respecting umask when extracting crate archives

CVSS3: 7.9
EPSS: Низкий
ubuntu логотип

CVE-2023-38497

около 2 лет назад

Cargo downloads the Rust project’s dependencies and compiles the project. Cargo prior to version 0.72.2, bundled with Rust prior to version 1.71.1, did not respect the umask when extracting crate archives on UNIX-like systems. If the user downloaded a crate containing files writeable by any local user, another local user could exploit this to change the source code compiled and executed by the current user. To prevent existing cached extractions from being exploitable, the Cargo binary version 0.72.2 included in Rust 1.71.1 or later will purge caches generated by older Cargo versions automatically. As a workaround, configure one's system to prevent other local users from accessing the Cargo directory, usually located in `~/.cargo`.

CVSS3: 7.9
EPSS: Низкий
redhat логотип

CVE-2023-38497

около 2 лет назад

Cargo downloads the Rust project’s dependencies and compiles the project. Cargo prior to version 0.72.2, bundled with Rust prior to version 1.71.1, did not respect the umask when extracting crate archives on UNIX-like systems. If the user downloaded a crate containing files writeable by any local user, another local user could exploit this to change the source code compiled and executed by the current user. To prevent existing cached extractions from being exploitable, the Cargo binary version 0.72.2 included in Rust 1.71.1 or later will purge caches generated by older Cargo versions automatically. As a workaround, configure one's system to prevent other local users from accessing the Cargo directory, usually located in `~/.cargo`.

CVSS3: 6.7
EPSS: Низкий
nvd логотип

CVE-2023-38497

около 2 лет назад

Cargo downloads the Rust project’s dependencies and compiles the project. Cargo prior to version 0.72.2, bundled with Rust prior to version 1.71.1, did not respect the umask when extracting crate archives on UNIX-like systems. If the user downloaded a crate containing files writeable by any local user, another local user could exploit this to change the source code compiled and executed by the current user. To prevent existing cached extractions from being exploitable, the Cargo binary version 0.72.2 included in Rust 1.71.1 or later will purge caches generated by older Cargo versions automatically. As a workaround, configure one's system to prevent other local users from accessing the Cargo directory, usually located in `~/.cargo`.

CVSS3: 7.9
EPSS: Низкий
debian логотип

CVE-2023-38497

около 2 лет назад

Cargo downloads the Rust project\u2019s dependencies and compiles the ...

CVSS3: 7.9
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:3251-1

около 2 лет назад

Security update for rust1.71

EPSS: Низкий
redos логотип

ROS-20240729-09

около 1 года назад

Уязвимость rust

CVSS3: 7.3
EPSS: Низкий
rocky логотип

RLSA-2023:4634

почти 2 года назад

Important: rust security update

EPSS: Низкий
oracle-oval логотип

ELSA-2023-4635

почти 2 года назад

ELSA-2023-4635: rust-toolset:ol8 security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2023-4634

почти 2 года назад

ELSA-2023-4634: rust security update (IMPORTANT)

EPSS: Низкий
fstec логотип

BDU:2024-05823

около 2 лет назад

Уязвимость менеджера пакетов Cargo языка программирования Rust, позволяющая нарушителю выполнить произвольный код

CVSS3: 7.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-j3xp-wfr4-hx87

Cargo not respecting umask when extracting crate archives

CVSS3: 7.9
5%
Низкий
около 2 лет назад
ubuntu логотип
CVE-2023-38497

Cargo downloads the Rust project’s dependencies and compiles the project. Cargo prior to version 0.72.2, bundled with Rust prior to version 1.71.1, did not respect the umask when extracting crate archives on UNIX-like systems. If the user downloaded a crate containing files writeable by any local user, another local user could exploit this to change the source code compiled and executed by the current user. To prevent existing cached extractions from being exploitable, the Cargo binary version 0.72.2 included in Rust 1.71.1 or later will purge caches generated by older Cargo versions automatically. As a workaround, configure one's system to prevent other local users from accessing the Cargo directory, usually located in `~/.cargo`.

CVSS3: 7.9
5%
Низкий
около 2 лет назад
redhat логотип
CVE-2023-38497

Cargo downloads the Rust project’s dependencies and compiles the project. Cargo prior to version 0.72.2, bundled with Rust prior to version 1.71.1, did not respect the umask when extracting crate archives on UNIX-like systems. If the user downloaded a crate containing files writeable by any local user, another local user could exploit this to change the source code compiled and executed by the current user. To prevent existing cached extractions from being exploitable, the Cargo binary version 0.72.2 included in Rust 1.71.1 or later will purge caches generated by older Cargo versions automatically. As a workaround, configure one's system to prevent other local users from accessing the Cargo directory, usually located in `~/.cargo`.

CVSS3: 6.7
5%
Низкий
около 2 лет назад
nvd логотип
CVE-2023-38497

Cargo downloads the Rust project’s dependencies and compiles the project. Cargo prior to version 0.72.2, bundled with Rust prior to version 1.71.1, did not respect the umask when extracting crate archives on UNIX-like systems. If the user downloaded a crate containing files writeable by any local user, another local user could exploit this to change the source code compiled and executed by the current user. To prevent existing cached extractions from being exploitable, the Cargo binary version 0.72.2 included in Rust 1.71.1 or later will purge caches generated by older Cargo versions automatically. As a workaround, configure one's system to prevent other local users from accessing the Cargo directory, usually located in `~/.cargo`.

CVSS3: 7.9
5%
Низкий
около 2 лет назад
debian логотип
CVE-2023-38497

Cargo downloads the Rust project\u2019s dependencies and compiles the ...

CVSS3: 7.9
5%
Низкий
около 2 лет назад
suse-cvrf логотип
SUSE-SU-2023:3251-1

Security update for rust1.71

5%
Низкий
около 2 лет назад
redos логотип
ROS-20240729-09

Уязвимость rust

CVSS3: 7.3
5%
Низкий
около 1 года назад
rocky логотип
RLSA-2023:4634

Important: rust security update

5%
Низкий
почти 2 года назад
oracle-oval логотип
ELSA-2023-4635

ELSA-2023-4635: rust-toolset:ol8 security update (IMPORTANT)

почти 2 года назад
oracle-oval логотип
ELSA-2023-4634

ELSA-2023-4634: rust security update (IMPORTANT)

почти 2 года назад
fstec логотип
BDU:2024-05823

Уязвимость менеджера пакетов Cargo языка программирования Rust, позволяющая нарушителю выполнить произвольный код

CVSS3: 7.3
5%
Низкий
около 2 лет назад

Уязвимостей на страницу