openSUSE-SU-2019:2203-1
Dashboard / Vulnerabilities / openSUSE-SU-2019:2203-1
openSUSE-SU-2019:2203-1
Summary: Security update for rust
Details: This update for rust fixes the following issues: Rust was updated to version 1.36.0. Security issues fixed: - CVE-2019-12083: a standard method can be overridden violating Rust's safety guarantees and causing memory unsafety (bsc#1134978) - CVE-2018-1000622: rustdoc loads plugins from world writable directory allowing for arbitrary code execution (bsc#1100691) This update was imported from SUSE:SLE-15:Update.
References: https://lists.opensuse.org/archives/list/[email protected]/thread/MZOZ25VGM7BURWQNSR2QRJK6ZK2KHN2N/#MZOZ25VGM7BURWQNSR2QRJK6ZK2KHN2N, https://bugzilla.suse.com/1096945, https://bugzilla.suse.com/1100691, https://bugzilla.suse.com/1133283, https://bugzilla.suse.com/1134978, https://www.suse.com/security/cve/CVE-2018-1000622, https://www.suse.com/security/cve/CVE-2019-12083
Affected packages
Package
Name: rust
Purl: pkg:rpm/opensuse/rust&distro=openSUSE%20Leap%2015.1
Affected ranges
Type: ECOSYSTEM
Events:
