CVE-2024-48990 Information
Nov 20, 2024
cve
Description
Qualys discovered that needrestart before version 3.8 allows local attackers to execute arbitrary code as root by tricking needrestart into running the Python interpreter with an attacker-controlled PYTHONPATH environment variable.
Reference
https://www.cve.org/CVERecord?id=CVE-2024-48990 https://github.com/liske/needrestart/commit/fcc9a4401392231bef4ef5ed026a0d7a275149ab https://www.qualys.com/2024/11/19/needrestart/needrestart.txt
Share on: