Bug 31393 - cargo new security issue CVE-2022-46176
Summary: cargo new security issue CVE-2022-46176
Status: RESOLVED DUPLICATE of bug 30907
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: Cauldron
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: Rémi Verschelde
QA Contact: Sec team
URL:
Whiteboard: MGA8TOO
Keywords:
Depends on:
Blocks:
 
Reported: 2023-01-11 10:19 CET by Nicolas Salguero
Modified: 2023-01-18 01:03 CET (History)
0 users

See Also:
Source RPM: rust-1.66.0-1.mga9.src.rpm
CVE: CVE-2022-46176
Status comment: Fixed in version 1.66.1


Attachments

Description Nicolas Salguero 2023-01-11 10:19:35 CET
Hi,

Cargo does not perform SSH host key verification when cloning indexes and dependencies via SSH.  An attacker could exploit this to perform man-in-the-middle (MITM) attacks.  All Rust versions containing Cargo before 1.66.1 are vulnerable:
https://www.openwall.com/lists/oss-security/2023/01/10/3

Best regards,

Nico.
Nicolas Salguero 2023-01-11 10:22:33 CET

Whiteboard: (none) => MGA8TOO

Nicolas Salguero 2023-01-11 10:23:41 CET

CVE: (none) => CVE-2022-46176
Status comment: (none) => Fixed in version 1.66.1
Source RPM: (none) => rust-1.66.0-1.mga9.src.rpm

David Walser 2023-01-11 16:10:43 CET

Assignee: bugsquad => rverschelde

Comment 1 David Walser 2023-01-18 01:03:06 CET
Already had a security bug for rust.

*** This bug has been marked as a duplicate of bug 30907 ***

Resolution: (none) => DUPLICATE
Status: NEW => RESOLVED


Note You need to log in before you can comment on or make changes to this bug.