Beveiligingsadvies

CVE-2024-11003

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2024-11-19 17:36:36
Laatst bijgewerkt 2025-11-03 21:51:44
Toegewezen door canonical
CVSS-score 7.8
Status PUBLISHED

Beschrijving

Qualys discovered that needrestart, before version 3.8, passes unsanitized data to a library (Modules::ScanDeps) which expects safe input. This could allow a local attacker to execute arbitrary shell commands. Please see the related CVE-2024-10224 in Modules::ScanDeps.