Addison Crump discovered that Cargo incorrectly set file permissions on UNIX-like systems when extracting crate archives. If the crate would contain files writable by any user, a local attacker could possibly use this issue to execute code as another user.
{ "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro", "binaries": [ { "binary_version": "0.47.0-1~exp1ubuntu1~16.04.1+esm1", "binary_name": "cargo" }, { "binary_version": "0.47.0-1~exp1ubuntu1~16.04.1+esm1", "binary_name": "cargo-dbgsym" }, { "binary_version": "0.47.0-1~exp1ubuntu1~16.04.1+esm1", "binary_name": "cargo-doc" } ] }
{ "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro", "binaries": [ { "binary_version": "0.66.0+ds0ubuntu0.libgit2-0ubuntu0.18.04.1~esm1", "binary_name": "cargo" }, { "binary_version": "0.66.0+ds0ubuntu0.libgit2-0ubuntu0.18.04.1~esm1", "binary_name": "cargo-dbgsym" }, { "binary_version": "0.66.0+ds0ubuntu0.libgit2-0ubuntu0.18.04.1~esm1", "binary_name": "cargo-doc" } ] }
{ "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro", "binaries": [ { "binary_version": "0.67.1+ds0ubuntu0.libgit2-0ubuntu0.20.04.2+esm1", "binary_name": "cargo" }, { "binary_version": "0.67.1+ds0ubuntu0.libgit2-0ubuntu0.20.04.2+esm1", "binary_name": "cargo-dbgsym" }, { "binary_version": "0.67.1+ds0ubuntu0.libgit2-0ubuntu0.20.04.2+esm1", "binary_name": "cargo-doc" } ] }
{ "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro", "binaries": [ { "binary_version": "0.67.1+ds0ubuntu0.libgit2-0ubuntu0.22.04.2+esm1", "binary_name": "cargo" }, { "binary_version": "0.67.1+ds0ubuntu0.libgit2-0ubuntu0.22.04.2+esm1", "binary_name": "cargo-dbgsym" }, { "binary_version": "0.67.1+ds0ubuntu0.libgit2-0ubuntu0.22.04.2+esm1", "binary_name": "cargo-doc" } ] }