CVE-2024-48990
high · 7.8Qualys discovered that needrestart, before version 3.8, allows local attackers to execute arbitrary code as root by tricking needrestart into running the Python interpreter with an attacker-controlled PYTHONPATH environment variable.
7.8
CVSS
20.5%
EPSS (exploit prob.)
97th
EPSS percentile
2024-11-19
Published
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-427
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| needrestart_project | needrestart | < 3.8 |
Check a specific version with /api/v1/cve/match.
References
- https://github.com/liske/needrestart/commit/fcc9a4401392231bef4ef5ed026a0d7a275149ab
- https://www.cve.org/CVERecord?id=CVE-2024-48990
- https://www.qualys.com/2024/11/19/needrestart/needrestart.txt
- http://seclists.org/fulldisclosure/2024/Nov/17
- https://lists.debian.org/debian-lts-announce/2024/11/msg00014.html
- https://www.openwall.com/lists/oss-security/2024/11/19/1
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2024-48990