SUSE: 2019:2755-1 moderate: rust
Summary
This update for rust fixes the following issues: Rust was updated to version 1.36.0. Security issues fixed: - CVE-2019-12083: a standard method can be overridden violating Rust's safety guarantees and causing memory unsafety (bsc#1134978) - CVE-2018-1000622: rustdoc loads plugins from world writable directory allowing for arbitrary code execution (bsc#1100691) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Open Buildservice Development Tools 15-SP1: zypper in -t patch SUSE-SLE-Module-Development-Tools-OBS-15-SP1-2019-2755=1 - SUSE Linux Enterprise Module for Development Tools 15-SP1: zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP1-2019-2755=1 Package List: - SUSE Linux Enterprise Module for Open Buildservic...
Read the Full AdvisoryReferences
#1096945 #1100691 #1133283 #1134978
Cross- CVE-2018-1000622 CVE-2019-12083
Affected Products:
SUSE Linux Enterprise Module for Open Buildservice Development Tools 15-SP1
SUSE Linux Enterprise Module for Development Tools 15-SP1
https://www.suse.com/security/cve/CVE-2018-1000622.html
https://www.suse.com/security/cve/CVE-2019-12083.html
https://bugzilla.suse.com/1096945
https://bugzilla.suse.com/1100691
https://bugzilla.suse.com/1133283
https://bugzilla.suse.com/1134978