CVE-2022-36113 affects Cargo, the Rust package manager, allowing malicious packages to corrupt a file on a user's system during extraction. This vulnerability, rated 8.1 HIGH (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H), involves an attacker replacing the first two bytes of a file by leveraging a symbolic link within the package. While no active exploits or public exploit code are reported, and crates.io has server-side mitigations, the vulnerability highlights the inherent risk of untrusted dependencies in Rust projects due to build scripts and procedural macros. Rust 1.64 includes a fix, but no backports are planned for earlier versions.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.65.0CPE matchmatch criteria | cpe:2.3:a:rust-lang:cargo:*:*:*:*:*:rust:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.