VDB
CVE-2024-48990
CVE-2024-48990
PUBLISHED
CVSS 7.800000190734863 HIGH
Qualys discovered that needrestart, before version 3.8, allows local attackers to execute arbitrary code as root by tricking needrestart into running the Python interpreter with an attacker-controlled PYTHONPATH environment variable.
EPSS 20.45% · 97.3th percentile
Risk Scores
CVSS 3.1
7.800000190734863
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
20.45%
97.3th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| needrestart_project | needrestart | 0, 0 |
| needrestart_project | needrestart | 0, 0, 0 |
| needrestart | needrestart | 0, 0 |
Timeline
- Nov 19, 2024 Coalition ESS Score
- Nov 19, 2024 Coalition ESS Score
- Nov 19, 2024 CVE Published
- Nov 20, 2024 EPSS Score
- Nov 20, 2024 Coalition ESS Score
- Nov 20, 2024 Coalition ESS Score
- Nov 20, 2024 PoC Published
- Nov 21, 2024 PoC Published
- Nov 22, 2024 PoC Published
- Nov 22, 2024 PoC Published
- Nov 22, 2024 PoC Published
- Nov 22, 2024 PoC Published
References
- https://nvd.nist.gov/vuln/detail/CVE-2024-48990 advisory
- https://github.com/liske/needrestart/commit/fcc9a4401392231bef4ef5ed026a0d7a275149ab url
- https://lists.debian.org/debian-lts-announce/2024/11/msg00014.html url
- https://www.cve.org/CVERecord?id=CVE-2024-48990 url
- https://www.openwall.com/lists/oss-security/2024/11/19/1 url
- https://www.qualys.com/2024/11/19/needrestart/needrestart.txt url
- http://seclists.org/fulldisclosure/2024/Nov/17 url