Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-48992

Опубликовано: 19 нояб. 2024
Источник: debian
EPSS Низкий

Описание

Qualys discovered that needrestart, before version 3.8, allows local attackers to execute arbitrary code as root by tricking needrestart into running the Ruby interpreter with an attacker-controlled RUBYLIB environment variable.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
needrestartfixed3.7-3.1package

Примечания

  • https://www.qualys.com/2024/11/19/needrestart/needrestart.txt

  • Fixed by: https://github.com/liske/needrestart/commit/b5f25f6ec6e7dd0c5be249e4e45de4ee9ffe594f (v3.8)

EPSS

Процентиль: 93%
0.06607
Низкий

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 1 года назад

Qualys discovered that needrestart, before version 3.8, allows local attackers to execute arbitrary code as root by tricking needrestart into running the Ruby interpreter with an attacker-controlled RUBYLIB environment variable.

CVSS3: 7.8
nvd
больше 1 года назад

Qualys discovered that needrestart, before version 3.8, allows local attackers to execute arbitrary code as root by tricking needrestart into running the Ruby interpreter with an attacker-controlled RUBYLIB environment variable.

CVSS3: 7.8
github
больше 1 года назад

Qualys discovered that needrestart, before version 3.8, allows local attackers to execute arbitrary code as root by tricking needrestart into running the Ruby interpreter with an attacker-controlled RUBYLIB environment variable.

CVSS3: 7.8
fstec
больше 1 года назад

Уязвимость утилиты needrestart, связанная с неконтролируемым элементом пути поиска, позволяющая нарушителю выполнить произвольный код в контексте root-пользователя

EPSS

Процентиль: 93%
0.06607
Низкий