Main
Vulnerability Database
Exploits
ID:9226 - Exploit for Incorrect default permissions in Cargo - CVE-2023-38497
ID:9226 - Exploit for Incorrect default permissions in Cargo - CVE-2023-38497
Published: August 4, 2023
Vulnerability identifier: #VU78930
Vulnerability risk: Low
CVE-ID: CVE-2023-38497
CWE-ID: CWE-276
Exploitation vector: Local access
Vulnerable software:
Cargo
Cargo
Link to public exploit:
Vulnerability description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to Cargo does not respect the umask when extracting crate archives on UNIX-like systems. A local user can change the source code compiled and executed by the current user.
Remediation
Install updates from vendor's website.