Improper Verification of Cryptographic Signature in Cargo and Rust Programming Language - CVE-2022-46176
Published: January 24, 2023
Vulnerability identifier: #VU71491
CSH Severity: Medium
CVSS v4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-46176
CWE-ID: CWE-347
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform MitM attack.
The vulnerability exists due to Cargo does not perform SSH host key verification when cloning indexes and dependencies via SSH. A remote attacker can perform MitM attack.
Affected software
Cargo
Rust Programming Language
Gentoo Linux
Amazon Linux AMI
SUSE Manager Proxy
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Enterprise Storage
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Realtime Extension
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Module for Development Tools
SUSE Linux Enterprise Desktop
openSUSE Leap
openEuler
Fedora
rust1.65-debuginfo
rust1.65
cargo1.65
cargo1.65-debuginfo
cargo1.66-debuginfo
cargo1.66
rust1.66
rust1.66-debuginfo
rust
dev-lang/rust
dev-lang/rust-bin
cargo
clippy
rust-analyzer
rust-debuginfo
rust-debugsource
rust-help
rust-std-static
rustfmt
rust-debugger-common
rust-gdb
rust-lldb
rust-src
Rust Programming Language
Gentoo Linux
Amazon Linux AMI
SUSE Manager Proxy
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Enterprise Storage
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Realtime Extension
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Module for Development Tools
SUSE Linux Enterprise Desktop
openSUSE Leap
openEuler
Fedora
rust1.65-debuginfo
rust1.65
cargo1.65
cargo1.65-debuginfo
cargo1.66-debuginfo
cargo1.66
rust1.66
rust1.66-debuginfo
rust
dev-lang/rust
dev-lang/rust-bin
cargo
clippy
rust-analyzer
rust-debuginfo
rust-debugsource
rust-help
rust-std-static
rustfmt
rust-debugger-common
rust-gdb
rust-lldb
rust-src
How to mitigate CVE-2022-46176
Install updates from vendor's website.
Cargo - update to 0.67.1
Rust Programming Language - update to 1.66.1
rust1.65-debuginfo - update to 1.65.0-150300.7.9.1
rust1.65 - update to 1.65.0-150300.7.9.1
cargo1.65 - update to 1.65.0-150300.7.9.1
cargo1.65-debuginfo - update to 1.65.0-150300.7.9.1
cargo1.66-debuginfo - update to 1.66.0-150400.9.9.1
cargo1.66 - update to 1.66.0-150400.9.9.1
rust1.66 - update to 1.66.0-150400.9.9.1
rust1.66-debuginfo - update to 1.66.0-150400.9.9.1
rust - update to 1.66.1-1
rust - addressed in versions 1.66.1-1.fc36, 1.66.1-1.fc37
dev-lang/rust - update to 1.71.1
dev-lang/rust-bin - update to 1.71.1
rust - update to 1.76.0-1
cargo - update to 1.76.0-1
clippy - update to 1.76.0-1
rust-analyzer - update to 1.76.0-1
rust-debuginfo - update to 1.76.0-1
rust-debugsource - update to 1.76.0-1
rust-help - update to 1.76.0-1
rust-std-static - update to 1.76.0-1
rustfmt - update to 1.76.0-1
rust-debugger-common - update to 1.76.0-1
rust-gdb - update to 1.76.0-1
rust-lldb - update to 1.76.0-1
rust-src - update to 1.76.0-1
Rust Programming Language - update to 1.66.1
rust1.65-debuginfo - update to 1.65.0-150300.7.9.1
rust1.65 - update to 1.65.0-150300.7.9.1
cargo1.65 - update to 1.65.0-150300.7.9.1
cargo1.65-debuginfo - update to 1.65.0-150300.7.9.1
cargo1.66-debuginfo - update to 1.66.0-150400.9.9.1
cargo1.66 - update to 1.66.0-150400.9.9.1
rust1.66 - update to 1.66.0-150400.9.9.1
rust1.66-debuginfo - update to 1.66.0-150400.9.9.1
rust - update to 1.66.1-1
rust - addressed in versions 1.66.1-1.fc36, 1.66.1-1.fc37
dev-lang/rust - update to 1.71.1
dev-lang/rust-bin - update to 1.71.1
rust - update to 1.76.0-1
cargo - update to 1.76.0-1
clippy - update to 1.76.0-1
rust-analyzer - update to 1.76.0-1
rust-debuginfo - update to 1.76.0-1
rust-debugsource - update to 1.76.0-1
rust-help - update to 1.76.0-1
rust-std-static - update to 1.76.0-1
rustfmt - update to 1.76.0-1
rust-debugger-common - update to 1.76.0-1
rust-gdb - update to 1.76.0-1
rust-lldb - update to 1.76.0-1
rust-src - update to 1.76.0-1