Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-5742

Опубликовано: 28 апр. 2024
Источник: redhat
CVSS3: 6.7
EPSS Низкий

Описание

A vulnerability was found in GNU Nano that allows a possible privilege escalation through an insecure temporary file. If Nano is killed while editing, a file it saves to an emergency file with the permissions of the running user provides a window of opportunity for attackers to escalate privileges through a malicious symlink.

Отчет

For an attack to be successful, an attacker must be able to kill the Nano session of another user, hence this issue was rated as a Low severity issue.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10nanoNot affected
Red Hat Enterprise Linux 6nanoOut of support scope
Red Hat Enterprise Linux 7nanoOut of support scope
Red Hat Enterprise Linux 8nanoFixedRHSA-2024:698624.09.2024
Red Hat Enterprise Linux 9nanoFixedRHSA-2024:943012.11.2024

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-59
https://bugzilla.redhat.com/show_bug.cgi?id=2278574nano: running `chmod` and `chown` on the filename allows malicious user to replace the emergency file with a malicious symlink to a root-owned file

EPSS

Процентиль: 20%
0.00064
Низкий

6.7 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.7
ubuntu
около 1 года назад

A vulnerability was found in GNU Nano that allows a possible privilege escalation through an insecure temporary file. If Nano is killed while editing, a file it saves to an emergency file with the permissions of the running user provides a window of opportunity for attackers to escalate privileges through a malicious symlink.

CVSS3: 6.7
nvd
около 1 года назад

A vulnerability was found in GNU Nano that allows a possible privilege escalation through an insecure temporary file. If Nano is killed while editing, a file it saves to an emergency file with the permissions of the running user provides a window of opportunity for attackers to escalate privileges through a malicious symlink.

CVSS3: 6.7
msrc
9 месяцев назад

Описание отсутствует

CVSS3: 6.7
debian
около 1 года назад

A vulnerability was found in GNU Nano that allows a possible privilege ...

suse-cvrf
около 1 года назад

Security update for nano

EPSS

Процентиль: 20%
0.00064
Низкий

6.7 Medium

CVSS3