CVE-2018-1000622
Summary
| CVE | CVE-2018-1000622 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-07-09 20:29:00 UTC |
| Updated | 2023-11-07 02:51:00 UTC |
| Description | The Rust Programming Language rustdoc version Between 0.8 and 1.27.0 contains a CWE-427: Uncontrolled Search Path Element vulnerability in rustdoc plugins that can result in local code execution as a different user. This attack appear to be exploitable via using the --plugin flag without the --plugin-path flag. This vulnerability appears to have been fixed in 1.27.1. |
Risk And Classification
Problem Types: CWE-427
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Google Groups | CONFIRM | groups.google.com | Patch, Third Party Advisory |
| [security-announce] openSUSE-SU-2019:2294-1: moderate: Security update f | SUSE | lists.opensuse.org | |
| [security-announce] openSUSE-SU-2019:2244-1: moderate: Security update f | SUSE | lists.opensuse.org | |
| Google Groups | groups.google.com | ||
| [security-announce] openSUSE-SU-2019:2203-1: moderate: Security update f | SUSE | lists.opensuse.org | |
| Rust: Multiple vulnerabilities (GLSA 201812-11) — Gentoo security | GENTOO | security.gentoo.org | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 710225 Gentoo Linux Rust Multiple Vulnerabilities (GLSA 201812-11)