﻿id	summary	reporter	owner	description	type	status	priority	milestone	component	version	severity	resolution	keywords	cc
18382	rustc-1.71.1	ken@…	Douglas R. Reno	"This was announced on oss-security on Friday, [https://www.openwall.com/lists/oss-security/2023/08/03/2] but unless I'm missing something we don't seem to have spotted it.

Release notes at [https://blog.rust-lang.org/2023/08/03/Rust-1.71.1.html]

Cargo (all rust versions before 1.71.1) did not respect the umask during extraction, so if files were writable by any user on the system, and other security measures did not prevent it, anthr local user could replace or tweak the code, potentially achieving code execution the next time the project is run. CVE-2023-38497

To prevent existing cached extractions from being exploitable, the Cargo binary included in Rust 1.71.1 or later will purge the caches it tries to access if they were generated by older Cargo versions.


"	enhancement	closed	elevated	12.0	BOOK	git	medium	fixed		
