Описание
A flaw was found in nano. In environments with permissive umask settings, a local attacker can exploit incorrect directory permissions (0777 instead of 0700) for the ~/.local directory. This allows the attacker to inject a malicious .desktop launcher, which could lead to unintended actions or information disclosure if the launcher is subsequently processed.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | not-affected | 9.1-1 |
| esm-infra-legacy/trusty | not-affected | code not present |
| esm-infra-legacy/xenial | not-affected | code not present |
| esm-infra/bionic | released | 2.9.3-2ubuntu0.1~esm2 |
| esm-infra/focal | released | 4.8-1ubuntu1.1+esm1 |
| esm-infra/xenial | ignored | end of ESM support, was needs-triage |
| jammy | released | 6.2-1ubuntu0.2 |
| noble | released | 7.2-2ubuntu0.2 |
| questing | released | 8.4-1ubuntu0.1 |
| resolute | released | 8.7.1-1ubuntu0.1 |
Показывать по
EPSS
2.5 Low
CVSS3
Связанные уязвимости
A flaw was found in nano. In environments with permissive umask settings, a local attacker can exploit incorrect directory permissions (0777 instead of 0700) for the `~/.local` directory. This allows the attacker to inject a malicious `.desktop` launcher, which could lead to unintended actions or information disclosure if the launcher is subsequently processed.
A flaw was found in nano. In environments with permissive umask settings, a local attacker can exploit incorrect directory permissions (0777 instead of 0700) for the `~/.local` directory. This allows the attacker to inject a malicious `.desktop` launcher, which could lead to unintended actions or information disclosure if the launcher is subsequently processed.
Nano: nano: local attacker can inject malicious .desktop launcher due to insecure directory permissions
A flaw was found in nano. In environments with permissive umask settin ...
A flaw was found in nano. In environments with permissive umask settings, a local attacker can exploit incorrect directory permissions (0777 instead of 0700) for the `~/.local` directory. This allows the attacker to inject a malicious `.desktop` launcher, which could lead to unintended actions or information disclosure if the launcher is subsequently processed.
EPSS
2.5 Low
CVSS3