Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2024-5742

Опубликовано: 12 июн. 2024
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS3: 6.7

Описание

A vulnerability was found in GNU Nano that allows a possible privilege escalation through an insecure temporary file. If Nano is killed while editing, a file it saves to an emergency file with the permissions of the running user provides a window of opportunity for attackers to escalate privileges through a malicious symlink.

РелизСтатусПримечание
devel

not-affected

8.0-1
esm-infra-legacy/trusty

not-affected

2.2.6-1ubuntu1+esm1
esm-infra/bionic

released

2.9.3-2ubuntu0.1~esm1
esm-infra/focal

not-affected

4.8-1ubuntu1.1
esm-infra/xenial

released

2.5.3-2ubuntu2+esm1
focal

released

4.8-1ubuntu1.1
jammy

released

6.2-1ubuntu0.1
mantic

ignored

end of life, was needed
noble

released

7.2-2ubuntu0.1
oracular

not-affected

8.0-1

Показывать по

EPSS

Процентиль: 10%
0.00037
Низкий

6.7 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.7
redhat
около 1 года назад

A vulnerability was found in GNU Nano that allows a possible privilege escalation through an insecure temporary file. If Nano is killed while editing, a file it saves to an emergency file with the permissions of the running user provides a window of opportunity for attackers to escalate privileges through a malicious symlink.

CVSS3: 6.7
nvd
около 1 года назад

A vulnerability was found in GNU Nano that allows a possible privilege escalation through an insecure temporary file. If Nano is killed while editing, a file it saves to an emergency file with the permissions of the running user provides a window of opportunity for attackers to escalate privileges through a malicious symlink.

CVSS3: 6.7
msrc
7 месяцев назад

Описание отсутствует

CVSS3: 6.7
debian
около 1 года назад

A vulnerability was found in GNU Nano that allows a possible privilege ...

suse-cvrf
около 1 года назад

Security update for nano

EPSS

Процентиль: 10%
0.00037
Низкий

6.7 Medium

CVSS3

Уязвимость CVE-2024-5742