PT-2024-8540 · Unknown+3 · Needrestart+3

Liske

+3

·

Published

2024-11-17

·

Updated

2024-12-24

·

CVE-2024-48992

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions needrestart versions prior to 3.8
Description The issue is related to an uncontrolled search path element in the needrestart utility. Exploitation of this issue may allow an attacker to execute arbitrary code in the context of the root user by manipulating the RUBYLIB environment variable. This can be achieved by tricking needrestart into running the Ruby interpreter with an attacker-controlled RUBYLIB variable.
Recommendations For versions prior to 3.8, update to version 3.8 or later to resolve the issue. As a temporary workaround, consider restricting the use of the RUBYLIB environment variable to minimize the risk of exploitation.

Exploit

Fix

Uncontrolled Search Path Element

Weakness Enumeration

Related Identifiers

BDU:2024-10107
CVE-2024-48992
DLA-3957-1
DLA-3957-2
DSA-5815-1
DSA-5815-2
USN-7117-1
USN-7117-2
USN-7117-3

Affected Products

Astra Linux
Linuxmint
Ubuntu
Needrestart