[Forgot Password]
Login  Register Subscribe

30480

 
 

423868

 
 

253164

 
 

909

 
 

197077

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS2023-2023-109 --- rust

ID: oval:org.secpod.oval:def:19500121Date: (C)2023-06-12   (M)2024-03-15
Class: PATCHFamily: unix




Cargo is a Rust package manager. The Rust Security Response WG was notified that Cargo did not perform SSH host key verification when cloning indexes and dependencies via SSH. An attacker could exploit this to perform man-in-the-middle attacks. This vulnerability has been assigned CVE-2022-46176. All Rust versions containing Cargo before 1.66.1 are vulnerable. Note that even if you don't explicitly use SSH for alternate registry indexes or crate dependencies, you might be affected by this vulnerability if you have configured git to replace HTTPS connections to GitHub with SSH , as that'd cause you to clone the crates.io index through SSH. Rust 1.66.1 will ensure Cargo checks the SSH host key and abort the connection if the server's public key is not already trusted. We recommend everyone to upgrade as soon as possible

Platform:
Amazon Linux 2023
Product:
rust
clippy
cargo
Reference:
ALAS2023-2023-109
CVE-2022-46176
CVE-2022-36113
CVE-2022-36114
CVE    3
CVE-2022-36113
CVE-2022-36114
CVE-2022-46176
CPE    3
cpe:/a:rust-lang:rust
cpe:/a:cargo:cargo
cpe:/a:clippy:clippy

© SecPod Technologies