PT-2016-4589 · Rust · Portaudio

Published

2016-08-01

·

Updated

2021-08-25

·

CVE-2016-10933

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions portaudio crate versions prior to 0.7.1
Description The issue concerns a man-in-the-middle problem due to the use of cleartext HTTP for downloading the source code. This allows an attacker to intercept the download and potentially achieve remote code execution (RCE) by replacing the original source code with a malicious archive.
Recommendations For portaudio crate versions prior to 0.7.1, update to version 0.7.1 or later to resolve the issue. As a temporary workaround, consider restricting the use of the build script that downloads the portaudio source over HTTP until a secure version is available. Avoid using the build script in untrusted networks to minimize the risk of exploitation.

Fix

Cleartext Transmission of Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-10933
GHSA-PQ6V-X7GP-7776
RUSTSEC-2016-0003

Affected Products

Portaudio