Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-5742

Опубликовано: 12 июн. 2024
Источник: debian
EPSS Низкий

Описание

A vulnerability was found in GNU Nano that allows a possible privilege escalation through an insecure temporary file. If Nano is killed while editing, a file it saves to an emergency file with the permissions of the running user provides a window of opportunity for attackers to escalate privileges through a malicious symlink.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
nanofixed8.0-1package
nanofixed7.2-1+deb12u1bookwormpackage
nanofixed5.4-2+deb11u3bullseyepackage

Примечания

  • Introduced by: https://git.savannah.gnu.org/cgit/nano.git/commit/?id=123110c5dc3e0d8c60a4ff0121056e301f503706 (v2.1.99pre2)

  • Fixed by: https://git.savannah.gnu.org/cgit/nano.git/commit/?id=5e7a3c2e7e118c7f12d5dfda9f9140f638976aa2 (v8.0)

EPSS

Процентиль: 10%
0.00037
Низкий

Связанные уязвимости

CVSS3: 6.7
ubuntu
около 1 года назад

A vulnerability was found in GNU Nano that allows a possible privilege escalation through an insecure temporary file. If Nano is killed while editing, a file it saves to an emergency file with the permissions of the running user provides a window of opportunity for attackers to escalate privileges through a malicious symlink.

CVSS3: 6.7
redhat
около 1 года назад

A vulnerability was found in GNU Nano that allows a possible privilege escalation through an insecure temporary file. If Nano is killed while editing, a file it saves to an emergency file with the permissions of the running user provides a window of opportunity for attackers to escalate privileges through a malicious symlink.

CVSS3: 6.7
nvd
около 1 года назад

A vulnerability was found in GNU Nano that allows a possible privilege escalation through an insecure temporary file. If Nano is killed while editing, a file it saves to an emergency file with the permissions of the running user provides a window of opportunity for attackers to escalate privileges through a malicious symlink.

CVSS3: 6.7
msrc
7 месяцев назад

Описание отсутствует

suse-cvrf
около 1 года назад

Security update for nano

EPSS

Процентиль: 10%
0.00037
Низкий