VulnerabilityModified
CVE-2024-48990
Qualys discovered that needrestart, before version 3.8, allows local attackers to execute arbitrary code as root by tricking needrestart into running the Python interpreter with an attacker-controlled PYTHONPATH environment variable.
HIGH 7.8EPSS 20.5%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 20.5%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
Qualys discovered that needrestart, before version 3.8, allows local attackers to execute arbitrary code as root by tricking needrestart into running the Python interpreter with an attacker-controlled PYTHONPATH environment variable.
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 20.45% probability · 97th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-427
- Affected
- needrestart project/needrestart
- Source
- security@ubuntu.com
References
- https://github.com/liske/needrestart/commit/fcc9a4401392231bef4ef5ed026a0d7a275149abPatch
- https://www.cve.org/CVERecord?id=CVE-2024-48990VDB Entry
- https://www.qualys.com/2024/11/19/needrestart/needrestart.txtThird Party Advisory
- http://seclists.org/fulldisclosure/2024/Nov/17
- https://lists.debian.org/debian-lts-announce/2024/11/msg00014.html
- https://www.openwall.com/lists/oss-security/2024/11/19/1Mailing List
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.