Ubuntu Security Update USN-8139-1: cargo-c vulnerability

LinuxBot

Member
Joined
Apr 25, 2017
Messages
6,385
Reaction score
94
Credits
-1,257
It was discovered that tar-rs embedded in cargo-c incorrectly handled symlinks when unpacking a tar archive. If a user or automated system were tricked into processing a specially crafted tar archive, a remote attacker could use this issue to modify permissions of arbitrary directories outside the extraction root, and possibly escalate privileges.

Continue reading...
 


Follow Linux.org

Staff online

Members online


Latest posts

Top