Packages
- cargo - Rust package manager
- rust-cargo - Rust package manager - feature "openssl"
Details
Addison Crump discovered that Cargo incorrectly set file permissions
on UNIX-like systems when extracting crate archives. If the crate would
contain files writable by any user, a local attacker could possibly use
this issue to execute code as another user.
Addison Crump discovered that Cargo incorrectly set file permissions
on UNIX-like systems when extracting crate archives. If the crate would
contain files writable by any user, a local attacker could possibly use
this issue to execute code as another user.
Update instructions
In general, a standard system update will make all the necessary changes.
Learn more about how to get the fixes.The problem can be corrected by updating your system to the following package versions:
Ubuntu Release | Package Version | ||
---|---|---|---|
22.04 jammy | cargo – 0.67.1+ds0ubuntu0.libgit2-0ubuntu0.22.04.2+esm1 | ||
librust-cargo+openssl-dev – 0.57.0-1ubuntu0.1~esm1 | |||
librust-cargo-dev – 0.57.0-1ubuntu0.1~esm1 | |||
20.04 focal | cargo – 0.67.1+ds0ubuntu0.libgit2-0ubuntu0.20.04.2+esm1 | ||
18.04 bionic | cargo – 0.66.0+ds0ubuntu0.libgit2-0ubuntu0.18.04.1~esm1 | ||
16.04 xenial | cargo – 0.47.0-1~exp1ubuntu1~16.04.1+esm1 |
Reduce your security exposure
Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines.