ALSA-2021:4590

See a problem?
Import Source
https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux8/ALSA-2021:4590.json
JSON Data
https://api.osv.dev/v1/vulns/ALSA-2021:4590
Related
Published
2021-11-10T08:37:57Z
Modified
2021-11-12T17:54:17Z
Summary
Moderate: rust-toolset:rhel8 security update
Details

Rust Toolset provides the Rust programming language compiler rustc, the cargo build tool and dependency manager, and required libraries.

Security Fix(es):

  • Developer environment: Unicode's bidirectional (BiDi) override characters can cause trojan source attacks (CVE-2021-42574)

The following changes were introduced in rust in order to facilitate detection of BiDi Unicode characters:

Rust introduces two new lints to detect and reject code containing the affected codepoints. These new deny-by-default lints detect affected codepoints in string literals and comments. The lints will prevent source code file containing these codepoints from being compiled. If your code has legitimate uses for the codepoints we recommend replacing them with the related escape sequence. The error messages will suggest the right escapes to use.

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

References

Affected packages

AlmaLinux:8

cargo

Package

Name
cargo
Purl
pkg:rpm/almalinux/cargo

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.54.0-3.module_el8.5.0+2599+d655d86c

Database specific

source

"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux8/ALSA-2021:4590.json"

cargo-doc

Package

Name
cargo-doc
Purl
pkg:rpm/almalinux/cargo-doc

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.54.0-3.module_el8.5.0+2599+d655d86c

Database specific

source

"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux8/ALSA-2021:4590.json"

clippy

Package

Name
clippy
Purl
pkg:rpm/almalinux/clippy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.54.0-3.module_el8.5.0+2599+d655d86c

Database specific

source

"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux8/ALSA-2021:4590.json"

rls

Package

Name
rls
Purl
pkg:rpm/almalinux/rls

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.54.0-3.module_el8.5.0+2599+d655d86c

Database specific

source

"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux8/ALSA-2021:4590.json"

rust

Package

Name
rust
Purl
pkg:rpm/almalinux/rust

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.54.0-3.module_el8.5.0+2599+d655d86c

Database specific

source

"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux8/ALSA-2021:4590.json"

rust-analysis

Package

Name
rust-analysis
Purl
pkg:rpm/almalinux/rust-analysis

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.54.0-3.module_el8.5.0+2599+d655d86c

Database specific

source

"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux8/ALSA-2021:4590.json"

rust-debugger-common

Package

Name
rust-debugger-common
Purl
pkg:rpm/almalinux/rust-debugger-common

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.54.0-3.module_el8.5.0+2599+d655d86c

Database specific

source

"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux8/ALSA-2021:4590.json"

rust-doc

Package

Name
rust-doc
Purl
pkg:rpm/almalinux/rust-doc

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.54.0-3.module_el8.5.0+2599+d655d86c

Database specific

source

"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux8/ALSA-2021:4590.json"

rust-gdb

Package

Name
rust-gdb
Purl
pkg:rpm/almalinux/rust-gdb

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.54.0-3.module_el8.5.0+2599+d655d86c

Database specific

source

"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux8/ALSA-2021:4590.json"

rust-lldb

Package

Name
rust-lldb
Purl
pkg:rpm/almalinux/rust-lldb

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.54.0-3.module_el8.5.0+2599+d655d86c

Database specific

source

"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux8/ALSA-2021:4590.json"

rust-src

Package

Name
rust-src
Purl
pkg:rpm/almalinux/rust-src

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.54.0-3.module_el8.5.0+2599+d655d86c

Database specific

source

"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux8/ALSA-2021:4590.json"

rust-std-static

Package

Name
rust-std-static
Purl
pkg:rpm/almalinux/rust-std-static

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.54.0-3.module_el8.5.0+2599+d655d86c

Database specific

source

"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux8/ALSA-2021:4590.json"

rust-std-static-wasm32-unknown-unknown

Package

Name
rust-std-static-wasm32-unknown-unknown
Purl
pkg:rpm/almalinux/rust-std-static-wasm32-unknown-unknown

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.54.0-3.module_el8.5.0+2599+d655d86c

Database specific

source

"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux8/ALSA-2021:4590.json"

rust-toolset

Package

Name
rust-toolset
Purl
pkg:rpm/almalinux/rust-toolset

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.54.0-1.module_el8.5.0+2599+d655d86c

Database specific

source

"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux8/ALSA-2021:4590.json"

rustfmt

Package

Name
rustfmt
Purl
pkg:rpm/almalinux/rustfmt

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.54.0-3.module_el8.5.0+2599+d655d86c

Database specific

source

"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux8/ALSA-2021:4590.json"