Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-5742

Опубликовано: 28 апр. 2024
Источник: redhat
CVSS3: 6.7

Описание

A vulnerability was found in GNU Nano that allows a possible privilege escalation through an insecure temporary file. If Nano is killed while editing, a file it saves to an emergency file with the permissions of the running user provides a window of opportunity for attackers to escalate privileges through a malicious symlink.

Отчет

For an attack to be successful, an attacker must be able to kill the Nano session of another user, hence this issue was rated as a Low severity issue.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10nanoNot affected
Red Hat Enterprise Linux 6nanoOut of support scope
Red Hat Enterprise Linux 7nanoOut of support scope
Red Hat Enterprise Linux 8nanoFixedRHSA-2024:698624.09.2024
Red Hat Enterprise Linux 9nanoFixedRHSA-2024:943012.11.2024

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-59
https://bugzilla.redhat.com/show_bug.cgi?id=2278574nano: running `chmod` and `chown` on the filename allows malicious user to replace the emergency file with a malicious symlink to a root-owned file

6.7 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.7
ubuntu
около 2 лет назад

A vulnerability was found in GNU Nano that allows a possible privilege escalation through an insecure temporary file. If Nano is killed while editing, a file it saves to an emergency file with the permissions of the running user provides a window of opportunity for attackers to escalate privileges through a malicious symlink.

CVSS3: 6.7
nvd
около 2 лет назад

A vulnerability was found in GNU Nano that allows a possible privilege escalation through an insecure temporary file. If Nano is killed while editing, a file it saves to an emergency file with the permissions of the running user provides a window of opportunity for attackers to escalate privileges through a malicious symlink.

CVSS3: 6.7
msrc
больше 1 года назад

Описание отсутствует

CVSS3: 6.7
debian
около 2 лет назад

A vulnerability was found in GNU Nano that allows a possible privilege ...

suse-cvrf
около 2 лет назад

Security update for nano

6.7 Medium

CVSS3