Cargo 安全公告 (CVE-2023-38497)
原文英文,约600词,阅读约需2分钟。发表于: 。This is a cross-post of the official security advisory. The official advisory contains a signed version with our PGP key, as well. The Rust Security Response WG was notified that Cargo did not...
Rust安全响应工作组收到通知,Cargo在UNIX-like系统上提取crate存档时没有遵守umask,可能导致代码执行漏洞。