LOW
GHSA-mc8h-8q98-g5hr
Race Condition Enabling Link Following and Time-of-check Time-of-use (TOCTOU) Race Condition in remove_dir_all
Details
The `remove_dir_all` crate is a Rust library that offers additional features over the Rust standard library `fs::remove_dir_all` function. It suffers the same class of failure as the code it was layering over: TOCTOU race conditions, with the ability to cause arbitrary paths to be deleted by substituting a symlink for a path after the type of the path was checked.
Thanks to the Rust security team for identifying the problem and alerting us to it.
Are you affected?
Enter the version of the package you're using.
Affected packages
crates.io/remove_dir_all
Introduced in:
0Fixed in: 0.8.0Upgrade remove_dir_all to 0.8.0 or newer (ecosystem crates.io).