Web: https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-36114

Sept. 14, 2022, 6:15 p.m. |

National Vulnerability Database nist.gov

Cargo is a package manager for the rust programming language. It was discovered that Cargo did not limit the amount of data extracted from compressed archives. An attacker could upload to an alternate registry a specially crafted package that extracts way more data than its size (also known as a "zip bomb"), exhausting the disk space on the machine using Cargo to download the package. Note that by design Cargo allows code execution at build time, due to build scripts …

cargo cve

Cybersecurity Engineer

@ Apercen Partners LLC | Folsom, CA

IDM Sr. Security Developer

@ The Ohio State University | Columbus, OH, United States

IT Security Engineer

@ Stylitics | New York City

Information Security Engineer

@ VDA Labs | Remote

Information Security Analyst

@ Metropolitan Transportation Commission | San Francisco, CA

Director of Security Operations, CISO office

@ Okcoin | San Jose, California, United States

Systems Security Engineer

@ Synctera | Canada or US Remote

Cyberark Senior Consultant I | Remote, Canada

@ Optiv | Toronto, ON

Privacy & Cybersecurity Counsel

@ Brightspeed | Charlotte, NC, United States

Sr/Staff Threat Researcher

@ SecurityScorecard | Remote (US/Canada)

Consultant SOC / CERT H/F

@ Hifield | Sèvres, France

SOC Analyst

@ Starling Bank | Southampton, England, United Kingdom