PT-2024-8538 · Unknown+3 · Needrestart+3

Liske

+3

·

Published

2024-11-17

·

Updated

2024-12-22

·

CVE-2024-11003

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions needrestart versions prior to 3.8
Description The issue is related to needrestart passing unsanitized data to a library, which expects safe input. This could allow a local attacker to execute arbitrary shell commands with root privileges.
Recommendations For versions prior to 3.8, update to version 3.8 or later to resolve the issue. As a temporary workaround, consider restricting the use of the needrestart utility until a patch is applied. Avoid using the needrestart utility with unsanitized input data to minimize the risk of exploitation.

Exploit

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-10105
CVE-2024-11003
DLA-3957-1
DLA-3957-2
DSA-5815-1
DSA-5815-2
USN-7117-1
USN-7117-2
USN-7117-3

Affected Products

Astra Linux
Linuxmint
Ubuntu
Needrestart