CVE-2024-48992 Information
Nov 20, 2024
cve
Description
Qualys discovered that needrestart before version 3.8 allows local attackers to execute arbitrary code as root by tricking needrestart into running the Ruby interpreter with an attacker-controlled RUBYLIB environment variable.
Reference
https://www.cve.org/CVERecord?id=CVE-2024-48992 https://github.com/liske/needrestart/commit/b5f25f6ec6e7dd0c5be249e4e45de4ee9ffe594f https://www.qualys.com/2024/11/19/needrestart/needrestart.txt
Share on: