CVE-2024-48990
Qualys discovered that needrestart, before version 3.8, allows local attackers to execute arbitrary code as root by tricking needrestart into running the Python interpreter with an attacker-controlled PYTHONPATH environment variable.
- Affected products
- Astra Linux, Linuxmint, Ubuntu, Needrestart
- Needrestart Project Needrestart
- < 3.8
- Fix
- Available
- CVSS 3.1
- 7.8 HIGH
- EPSS
- 19.9% (97th percentile)
- Weakness
- CWE-427
- NVD status
- Modified
- Published
- 2024-11-19
Workaround
Edit /etc/needrestart/needrestart.conf so that the following line appears after "# Disable interpreter scanners." and reboot: $nrconf{interpscan} = 0;
CVE-2024-48990 at NVD
15 known exploits for CVE-2024-48990
Proof-of-concept code and exploit modules indexed by Sploitus
Exploit for Uncontrolled Search Path Element in Needrestart_Project Needrestart
Exploit for Uncontrolled Search Path Element in Needrestart_Project Needrestart
Exploit for Uncontrolled Search Path Element in Needrestart_Project Needrestart
Exploit for Uncontrolled Search Path Element in Needrestart_Project Needrestart
Exploit for Uncontrolled Search Path Element in Needrestart_Project Needrestart
Exploit for Uncontrolled Search Path Element in Needrestart_Project Needrestart
Exploit for Uncontrolled Search Path Element in Needrestart_Project Needrestart
Exploit for Uncontrolled Search Path Element in Needrestart_Project Needrestart
Exploit for Uncontrolled Search Path Element in Needrestart_Project Needrestart
Exploit for Uncontrolled Search Path Element in Needrestart_Project Needrestart
needrestart Local Privilege Escalation Vulnerability
needrestart Local Privilege Escalation
Exploit for Uncontrolled Search Path Element in Needrestart_Project Needrestart
Exploit for Uncontrolled Search Path Element in Needrestart_Project Needrestart
Ubuntu needrestart Privilege Escalation