CVE-2023-38497
Severity
7.3HIGH
EPSS
5.7%
top 9.63%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 4
Latest updateAug 8
Description
Cargo downloads the Rust project’s dependencies and compiles the project. Cargo prior to version 0.72.2, bundled with Rust prior to version 1.71.1, did not respect the umask when extracting crate archives on UNIX-like systems. If the user downloaded a crate containing files writeable by any local user, another local user could exploit this to change the source code compiled and executed by the current user. To prevent existing cached extractions from being exploitable, the Cargo binary version 0…
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:NExploitability: 1.5 | Impact: 5.8
Affected Packages4 packages
Also affects: Fedora 38
Patches
🔴Vulnerability Details
4OSV
▶
📋Vendor Advisories
4Debian▶
CVE-2023-38497: cargo - Cargo downloads the Rust project’s dependencies and compiles the project. Cargo ...↗2023