Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-48991

Опубликовано: 19 нояб. 2024
Источник: nvd
CVSS3: 7.8
EPSS Низкий

Описание

Qualys discovered that needrestart, before version 3.8, allows local attackers to execute arbitrary code as root by winning a race condition and tricking needrestart into running their own, fake Python interpreter (instead of the system's real Python interpreter). The initial security fix (6ce6136) introduced a regression which was subsequently resolved (42af5d3).

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:needrestart_project:needrestart:*:*:*:*:*:*:*:*
Версия до 3.8 (исключая)

EPSS

Процентиль: 48%
0.0025
Низкий

7.8 High

CVSS3

Дефекты

CWE-362

Связанные уязвимости

CVSS3: 7.8
ubuntu
около 1 года назад

Qualys discovered that needrestart, before version 3.8, allows local attackers to execute arbitrary code as root by winning a race condition and tricking needrestart into running their own, fake Python interpreter (instead of the system's real Python interpreter). The initial security fix (6ce6136) introduced a regression which was subsequently resolved (42af5d3).

CVSS3: 7.8
debian
около 1 года назад

Qualys discovered that needrestart, before version 3.8, allows local a ...

CVSS3: 7.8
github
около 1 года назад

Qualys discovered that needrestart, before version 3.8, allows local attackers to execute arbitrary code as root by winning a race condition and tricking needrestart into running their own, fake Python interpreter (instead of the system's real Python interpreter).

CVSS3: 7.8
fstec
около 1 года назад

Уязвимость утилиты needrestart, связанная с конкурентным доступом к ресурсу (состояние гонки), позволяющая нарушителю выполнить произвольный код в контексте root-пользователя

EPSS

Процентиль: 48%
0.0025
Низкий

7.8 High

CVSS3

Дефекты

CWE-362