Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4696-66c4-2gvx

Опубликовано: 19 нояб. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 7.8

Описание

Qualys discovered that needrestart, before version 3.8, allows local attackers to execute arbitrary code as root by winning a race condition and tricking needrestart into running their own, fake Python interpreter (instead of the system's real Python interpreter).

Qualys discovered that needrestart, before version 3.8, allows local attackers to execute arbitrary code as root by winning a race condition and tricking needrestart into running their own, fake Python interpreter (instead of the system's real Python interpreter).

EPSS

Процентиль: 48%
0.0025
Низкий

7.8 High

CVSS3

Дефекты

CWE-362

Связанные уязвимости

CVSS3: 7.8
ubuntu
около 1 года назад

Qualys discovered that needrestart, before version 3.8, allows local attackers to execute arbitrary code as root by winning a race condition and tricking needrestart into running their own, fake Python interpreter (instead of the system's real Python interpreter). The initial security fix (6ce6136) introduced a regression which was subsequently resolved (42af5d3).

CVSS3: 7.8
nvd
около 1 года назад

Qualys discovered that needrestart, before version 3.8, allows local attackers to execute arbitrary code as root by winning a race condition and tricking needrestart into running their own, fake Python interpreter (instead of the system's real Python interpreter). The initial security fix (6ce6136) introduced a regression which was subsequently resolved (42af5d3).

CVSS3: 7.8
debian
около 1 года назад

Qualys discovered that needrestart, before version 3.8, allows local a ...

CVSS3: 7.8
fstec
около 1 года назад

Уязвимость утилиты needrestart, связанная с конкурентным доступом к ресурсу (состояние гонки), позволяющая нарушителю выполнить произвольный код в контексте root-пользователя

EPSS

Процентиль: 48%
0.0025
Низкий

7.8 High

CVSS3

Дефекты

CWE-362