Логотип exploitDog
bind:"CVE-2023-38497"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2023-38497"

Количество 11

Количество 11

ubuntu логотип

CVE-2023-38497

почти 2 года назад

Cargo downloads the Rust project’s dependencies and compiles the project. Cargo prior to version 0.72.2, bundled with Rust prior to version 1.71.1, did not respect the umask when extracting crate archives on UNIX-like systems. If the user downloaded a crate containing files writeable by any local user, another local user could exploit this to change the source code compiled and executed by the current user. To prevent existing cached extractions from being exploitable, the Cargo binary version 0.72.2 included in Rust 1.71.1 or later will purge caches generated by older Cargo versions automatically. As a workaround, configure one's system to prevent other local users from accessing the Cargo directory, usually located in `~/.cargo`.

CVSS3: 7.9
EPSS: Низкий
redhat логотип

CVE-2023-38497

почти 2 года назад

Cargo downloads the Rust project’s dependencies and compiles the project. Cargo prior to version 0.72.2, bundled with Rust prior to version 1.71.1, did not respect the umask when extracting crate archives on UNIX-like systems. If the user downloaded a crate containing files writeable by any local user, another local user could exploit this to change the source code compiled and executed by the current user. To prevent existing cached extractions from being exploitable, the Cargo binary version 0.72.2 included in Rust 1.71.1 or later will purge caches generated by older Cargo versions automatically. As a workaround, configure one's system to prevent other local users from accessing the Cargo directory, usually located in `~/.cargo`.

CVSS3: 6.7
EPSS: Низкий
nvd логотип

CVE-2023-38497

почти 2 года назад

Cargo downloads the Rust project’s dependencies and compiles the project. Cargo prior to version 0.72.2, bundled with Rust prior to version 1.71.1, did not respect the umask when extracting crate archives on UNIX-like systems. If the user downloaded a crate containing files writeable by any local user, another local user could exploit this to change the source code compiled and executed by the current user. To prevent existing cached extractions from being exploitable, the Cargo binary version 0.72.2 included in Rust 1.71.1 or later will purge caches generated by older Cargo versions automatically. As a workaround, configure one's system to prevent other local users from accessing the Cargo directory, usually located in `~/.cargo`.

CVSS3: 7.9
EPSS: Низкий
debian логотип

CVE-2023-38497

почти 2 года назад

Cargo downloads the Rust project\u2019s dependencies and compiles the ...

CVSS3: 7.9
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:3251-1

почти 2 года назад

Security update for rust1.71

EPSS: Низкий
redos логотип

ROS-20240729-09

11 месяцев назад

Уязвимость rust

CVSS3: 7.3
EPSS: Низкий
rocky логотип

RLSA-2023:4634

почти 2 года назад

Important: rust security update

EPSS: Низкий
github логотип

GHSA-j3xp-wfr4-hx87

почти 2 года назад

Cargo not respecting umask when extracting crate archives

CVSS3: 7.9
EPSS: Низкий
oracle-oval логотип

ELSA-2023-4635

почти 2 года назад

ELSA-2023-4635: rust-toolset:ol8 security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2023-4634

почти 2 года назад

ELSA-2023-4634: rust security update (IMPORTANT)

EPSS: Низкий
fstec логотип

BDU:2024-05823

почти 2 года назад

Уязвимость менеджера пакетов Cargo языка программирования Rust, позволяющая нарушителю выполнить произвольный код

CVSS3: 7.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2023-38497

Cargo downloads the Rust project’s dependencies and compiles the project. Cargo prior to version 0.72.2, bundled with Rust prior to version 1.71.1, did not respect the umask when extracting crate archives on UNIX-like systems. If the user downloaded a crate containing files writeable by any local user, another local user could exploit this to change the source code compiled and executed by the current user. To prevent existing cached extractions from being exploitable, the Cargo binary version 0.72.2 included in Rust 1.71.1 or later will purge caches generated by older Cargo versions automatically. As a workaround, configure one's system to prevent other local users from accessing the Cargo directory, usually located in `~/.cargo`.

CVSS3: 7.9
5%
Низкий
почти 2 года назад
redhat логотип
CVE-2023-38497

Cargo downloads the Rust project’s dependencies and compiles the project. Cargo prior to version 0.72.2, bundled with Rust prior to version 1.71.1, did not respect the umask when extracting crate archives on UNIX-like systems. If the user downloaded a crate containing files writeable by any local user, another local user could exploit this to change the source code compiled and executed by the current user. To prevent existing cached extractions from being exploitable, the Cargo binary version 0.72.2 included in Rust 1.71.1 or later will purge caches generated by older Cargo versions automatically. As a workaround, configure one's system to prevent other local users from accessing the Cargo directory, usually located in `~/.cargo`.

CVSS3: 6.7
5%
Низкий
почти 2 года назад
nvd логотип
CVE-2023-38497

Cargo downloads the Rust project’s dependencies and compiles the project. Cargo prior to version 0.72.2, bundled with Rust prior to version 1.71.1, did not respect the umask when extracting crate archives on UNIX-like systems. If the user downloaded a crate containing files writeable by any local user, another local user could exploit this to change the source code compiled and executed by the current user. To prevent existing cached extractions from being exploitable, the Cargo binary version 0.72.2 included in Rust 1.71.1 or later will purge caches generated by older Cargo versions automatically. As a workaround, configure one's system to prevent other local users from accessing the Cargo directory, usually located in `~/.cargo`.

CVSS3: 7.9
5%
Низкий
почти 2 года назад
debian логотип
CVE-2023-38497

Cargo downloads the Rust project\u2019s dependencies and compiles the ...

CVSS3: 7.9
5%
Низкий
почти 2 года назад
suse-cvrf логотип
SUSE-SU-2023:3251-1

Security update for rust1.71

5%
Низкий
почти 2 года назад
redos логотип
ROS-20240729-09

Уязвимость rust

CVSS3: 7.3
5%
Низкий
11 месяцев назад
rocky логотип
RLSA-2023:4634

Important: rust security update

5%
Низкий
почти 2 года назад
github логотип
GHSA-j3xp-wfr4-hx87

Cargo not respecting umask when extracting crate archives

CVSS3: 7.9
5%
Низкий
почти 2 года назад
oracle-oval логотип
ELSA-2023-4635

ELSA-2023-4635: rust-toolset:ol8 security update (IMPORTANT)

почти 2 года назад
oracle-oval логотип
ELSA-2023-4634

ELSA-2023-4634: rust security update (IMPORTANT)

почти 2 года назад
fstec логотип
BDU:2024-05823

Уязвимость менеджера пакетов Cargo языка программирования Rust, позволяющая нарушителю выполнить произвольный код

CVSS3: 7.3
5%
Низкий
почти 2 года назад

Уязвимостей на страницу