CVE-2022-30688
needrestart 0.8 through 3.5 before 3.6 is prone to local privilege escalation. Regexes to detect the Perl, Python, and Ruby interpreters are not anchored, allowing a local user to escalate privileges when needrestart tries to detect if interpreters are using old source files.
- Affected products
- Linuxmint, Ubuntu, Needrestart
- Needrestart Project Needrestart
- < 3.6
- Fix
- Available
- CVSS 3.1
- 7.8 HIGH
- EPSS
- 0.4% (34th percentile)
- NVD status
- Modified
- Published
- 2022-05-17
CVE-2022-30688 at NVD
2 known exploits for CVE-2022-30688
Proof-of-concept code and exploit modules indexed by Sploitus