标准库安全公告 (CVE-2024-43402)
原文英文,约400词,阅读约需2分钟。发表于: 。On April 9th, 2024, the Rust Security Response WG disclosed CVE-2024-24576, where std::process::Command incorrectly escaped arguments when invoking batch files on Windows. We were notified that...
Rust安全响应WG披露了CVE-2024-24576,即在Windows上调用批处理文件时,std::process::Command在转义参数时出现错误。修复不完整的严重性较低,需要特定条件才能触发。受影响的版本是所有1.81.0之前的Rust版本。