Sploitus

CVE-2024-11003

2 known exploits for CVE-2024-11003

Qualys discovered that needrestart, before version 3.8, passes unsanitized data to a library (Modules::ScanDeps) which expects safe input. This could allow a local attacker to execute arbitrary shell commands. Please see the related CVE-2024-10224 in Modules::ScanDeps.

Needrestart Project Needrestart
< 3.8
Fix
Available
CVSS 3.1
7.8 HIGH
EPSS
11.5% (96th percentile)
Weakness
CWE-78
NVD status
Modified
Published
2024-11-19

Workaround

Edit /etc/needrestart/needrestart.conf so that the following line appears after "# Disable interpreter scanners." and reboot: $nrconf{interpscan} = 0;

CVE-2024-11003 at NVD
Authoritative description, scoring and affected products

2 known exploits for CVE-2024-11003

Proof-of-concept code and exploit modules indexed by Sploitus