CVE-2018-1000622: High severity rust vulnerability
The Rust Programming Language rustdoc version Between 0.8 and 1.27.0 contains a CWE-427: Uncontrolled Search Path Element vulnerability in rustdoc plugins that can result in local code execution as a different user. This attack appear to be exploitable via using the --plugin flag without the --plugin-path flag. This vulnerability appears to have been fixed in 1.27.1.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2018-1000622?
CVE-2018-1000622 is a vulnerability in the Rust Programming Language rustdoc version Between 0.8 and 1.27.0 that allows for local code execution as a different user.
How severe is CVE-2018-1000622?
CVE-2018-1000622 is considered to be a high severity vulnerability with a CVSS score of 7.8.
What is the affected software?
The affected software is Rust Programming Language rustdoc version between 0.8 and 1.27.0.
How can CVE-2018-1000622 be exploited?
CVE-2018-1000622 can be exploited by using the --plugin flag without the --plugi…
Is there a fix available for CVE-2018-1000622?
Yes, updating to a version of Rust Programming Language rustdoc above 1.27.0 will fix the CVE-2018-1000622 vulnerability.