Rust vulnerability enables attackers to delete files and directories
Maintainers of the Rust programming language have warned of a critical vulnerability that enables attackers to delete files and directories.
In a security advisory, the Rust Security Response Working Group wrote:
“The Rust Security Response WG was notified that the std::fs::remove_dir_all standard library function is vulnerable to a race condition enabling symlink following (CWE-363).
An attacker could use this security issue to trick a privileged program into...
Recent Comments