news
Rust: News Mr_Figtree 1 year ago 100%

Security advisory for Cargo (CVE-2023-38497) | Rust Blog

blog.rust-lang.org

The Rust Security Response WG was notified that Cargo did not respect the umask when extracting crate archives on UNIX-like systems. If the user downloaded a crate containing files writeable by any local user, another local user could exploit this to change the source code compiled and executed by the current user.

5
0
Comments 0