Beveiligingsadvies

CVE-2024-48992

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2024-11-19 17:38:22
Laatst bijgewerkt 2025-11-03 22:22:13
Toegewezen door canonical
CVSS-score 7.8
Status PUBLISHED

Beschrijving

Qualys discovered that needrestart, before version 3.8, allows local attackers to execute arbitrary code as root by tricking needrestart into running the Ruby interpreter with an attacker-controlled RUBYLIB environment variable.