USN-6275-1: Cargo vulnerability
3 August 2023
Cargo could be made to run programs as your login if it installed a specially crafted crate.
Addison Crump discovered that Cargo incorrectly set file permissions
on UNIX-like systems when extracting crate archives. If the crate would
contain files writable by any user, a local attacker could possibly use
this issue to execute code as another user.
The problem can be corrected by updating your system to the following package versions:
- cargo - 0.67.1+ds0ubuntu0.libgit2-0ubuntu0.22.04.2+esm1
- librust-cargo+openssl-dev - 0.57.0-1ubuntu0.1~esm1
- librust-cargo-dev - 0.57.0-1ubuntu0.1~esm1
- cargo - 0.67.1+ds0ubuntu0.libgit2-0ubuntu0.20.04.2+esm1
- cargo - 0.66.0+ds0ubuntu0.libgit2-0ubuntu0.18.04.1~esm1
- cargo - 0.47.0-1~exp1ubuntu1~16.04.1+esm1
In general, a standard system update will make all the necessary changes.