Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-5742

Опубликовано: 28 апр. 2024
Источник: redhat
CVSS3: 6.7
EPSS Низкий

Описание

A vulnerability was found in GNU Nano that allows a possible privilege escalation through an insecure temporary file. If Nano is killed while editing, a file it saves to an emergency file with the permissions of the running user provides a window of opportunity for attackers to escalate privileges through a malicious symlink.

Отчет

For an attack to be successful, an attacker must be able to kill the Nano session of another user, hence this issue was rated as a Low severity issue.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6nanoOut of support scope
Red Hat Enterprise Linux 7nanoOut of support scope
Red Hat Enterprise Linux 8nanoFixedRHSA-2024:698624.09.2024
Red Hat Enterprise Linux 9nanoFixedRHSA-2024:943012.11.2024

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-59
https://bugzilla.redhat.com/show_bug.cgi?id=2278574nano: running `chmod` and `chown` on the filename allows malicious user to replace the emergency file with a malicious symlink to a root-owned file

EPSS

Процентиль: 10%
0.00037
Низкий

6.7 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.7
ubuntu
около 1 года назад

A vulnerability was found in GNU Nano that allows a possible privilege escalation through an insecure temporary file. If Nano is killed while editing, a file it saves to an emergency file with the permissions of the running user provides a window of opportunity for attackers to escalate privileges through a malicious symlink.

CVSS3: 6.7
nvd
около 1 года назад

A vulnerability was found in GNU Nano that allows a possible privilege escalation through an insecure temporary file. If Nano is killed while editing, a file it saves to an emergency file with the permissions of the running user provides a window of opportunity for attackers to escalate privileges through a malicious symlink.

CVSS3: 6.7
msrc
7 месяцев назад

Описание отсутствует

CVSS3: 6.7
debian
около 1 года назад

A vulnerability was found in GNU Nano that allows a possible privilege ...

suse-cvrf
около 1 года назад

Security update for nano

EPSS

Процентиль: 10%
0.00037
Низкий

6.7 Medium

CVSS3

Уязвимость CVE-2024-5742