First published: Thu Aug 03 2023(Updated: )
Addison Crump discovered that Cargo incorrectly set file permissions on UNIX-like systems when extracting crate archives. If the crate would contain files writable by any user, a local attacker could possibly use this issue to execute code as another user.
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/cargo | <0.67.1+ds0ubuntu0.libgit2-0ubuntu0.22.04.2+esm1 | 0.67.1+ds0ubuntu0.libgit2-0ubuntu0.22.04.2+esm1 |
=22.04 | ||
All of | ||
ubuntu/librust-cargo+openssl-dev | <0.57.0-1ubuntu0.1~esm1 | 0.57.0-1ubuntu0.1~esm1 |
=22.04 | ||
All of | ||
ubuntu/librust-cargo-dev | <0.57.0-1ubuntu0.1~esm1 | 0.57.0-1ubuntu0.1~esm1 |
=22.04 | ||
All of | ||
ubuntu/cargo | <0.67.1+ds0ubuntu0.libgit2-0ubuntu0.20.04.2+esm1 | 0.67.1+ds0ubuntu0.libgit2-0ubuntu0.20.04.2+esm1 |
=20.04 | ||
All of | ||
ubuntu/cargo | <0.66.0+ds0ubuntu0.libgit2-0ubuntu0.18.04.1~esm1 | 0.66.0+ds0ubuntu0.libgit2-0ubuntu0.18.04.1~esm1 |
=18.04 | ||
All of | ||
ubuntu/cargo | <0.47.0-1~exp1ubuntu1~16.04.1+esm1 | 0.47.0-1~exp1ubuntu1~16.04.1+esm1 |
=16.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this advisory is USN-6275-1.
The title of this advisory is USN-6275-1: Cargo vulnerability.
The vulnerability was discovered by Addison Crump.
The severity level of this vulnerability has not been provided.
You can fix this vulnerability by updating the affected software to the recommended versions mentioned in the advisory.