Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 662906

Summary: <dev-lang/rust-1.27.1: rustdoc loads plugins from world writable directory allowing for arbitrary code execution (CVE-2018-1000622)
Product: Gentoo Security Reporter: Thomas Deutschmann (RETIRED) <whissi>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: RESOLVED DUPLICATE    
Severity: normal CC: rust
Priority: Normal    
Version: unspecified   
Hardware: All   
OS: Linux   
Whiteboard: B2 [stable?]
Package list:
Runtime testing required: ---

Description Thomas Deutschmann (RETIRED) gentoo-dev 2018-08-05 23:45:48 UTC
Please see tracker bug 662904 for details.
Comment 1 Thomas Deutschmann (RETIRED) gentoo-dev 2018-08-05 23:48:39 UTC
@ Maintainer(s): Multiple fixed versions (>=dev-lang/rust-1.27.1) are already available in Gentoo repository. Please tell us which version we can stabilize.
Comment 2 Thomas Deutschmann (RETIRED) gentoo-dev 2018-08-15 17:15:39 UTC
No tracker bug needed/wanted.

*** This bug has been marked as a duplicate of bug 662904 ***