{"id":"MGASA-2025-0136","summary":"Updated rust packages fix security vulnerability","details":"The Rust Security Response WG was notified that the Rust standard\nlibrary did not properly escape arguments when invoking batch files\n(with the bat and cmd extensions) on Windows using the Command API. An\nattacker able to control the arguments passed to the spawned process\ncould execute arbitrary shell commands by bypassing the escaping.\nThe severity of this vulnerability is critical if you are invoking batch\nfiles on Windows with untrusted arguments. No other platform or use is\naffected.\nWe update to rust 1.78.0 for future mesa updates in mageia 9.\n","modified":"2026-04-16T00:10:28.785953542Z","published":"2025-04-17T17:37:29Z","upstream":["CVE-2024-24576"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2025-0136.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=34107"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2024/04/09/16"},{"type":"ADVISORY","url":"https://github.com/rust-lang/rust/security/advisories/GHSA-q455-m56c-85mh"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/N323QAEEUVTJ354BTVQ7UB6LYXUX2BCL/"},{"type":"WEB","url":"https://blog.rust-lang.org/2024/04/09/cve-2024-24576/"},{"type":"WEB","url":"https://github.com/rust-lang/rust/releases/tag/1.78.0"},{"type":"WEB","url":"https://github.com/rust-lang/rust/releases/tag/1.77.2"},{"type":"WEB","url":"https://github.com/rust-lang/rust/releases/tag/1.77.1"},{"type":"WEB","url":"https://github.com/rust-lang/rust/releases/tag/1.77.0"}],"affected":[{"package":{"name":"rust","ecosystem":"Mageia:9","purl":"pkg:rpm/mageia/rust?arch=source&distro=mageia-9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.78.0-1.mga9"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2025-0136.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}