Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7c65-3hqv-hvmm

Опубликовано: 19 нояб. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 7.8

Описание

Qualys discovered that needrestart, before version 3.8, allows local attackers to execute arbitrary code as root by tricking needrestart into running the Python interpreter with an attacker-controlled PYTHONPATH environment variable.

Qualys discovered that needrestart, before version 3.8, allows local attackers to execute arbitrary code as root by tricking needrestart into running the Python interpreter with an attacker-controlled PYTHONPATH environment variable.

EPSS

Процентиль: 95%
0.19394
Средний

7.8 High

CVSS3

Дефекты

CWE-427

Связанные уязвимости

CVSS3: 7.8
ubuntu
около 1 года назад

Qualys discovered that needrestart, before version 3.8, allows local attackers to execute arbitrary code as root by tricking needrestart into running the Python interpreter with an attacker-controlled PYTHONPATH environment variable.

CVSS3: 7.8
nvd
около 1 года назад

Qualys discovered that needrestart, before version 3.8, allows local attackers to execute arbitrary code as root by tricking needrestart into running the Python interpreter with an attacker-controlled PYTHONPATH environment variable.

CVSS3: 7.8
debian
около 1 года назад

Qualys discovered that needrestart, before version 3.8, allows local a ...

CVSS3: 7.8
fstec
около 1 года назад

Уязвимость утилиты needrestart, связанная с неконтролируемым элементом пути поиска, позволяющая нарушителю выполнить произвольный код в контексте root-пользователя

EPSS

Процентиль: 95%
0.19394
Средний

7.8 High

CVSS3

Дефекты

CWE-427