ID:9226 - Exploit for Incorrect default permissions in Cargo - CVE-2023-38497

 
Main Vulnerability Database Exploits ID:9226 - Exploit for Incorrect default permissions in Cargo - CVE-2023-38497

ID:9226 - Exploit for Incorrect default permissions in Cargo - CVE-2023-38497

Published: August 4, 2023


Vulnerability identifier: #VU78930
Vulnerability risk: Low
CVE-ID: CVE-2023-38497
CWE-ID: CWE-276
Exploitation vector: Local access
Vulnerable software:
Cargo

Link to public exploit:


Vulnerability description

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to Cargo does not respect the umask when extracting crate archives on UNIX-like systems. A local user can change the source code compiled and executed by the current user.


Remediation

Install updates from vendor's website.