CVE-2024-48992

Publication date

2024-11-19 17:38:22

Family

canonical

State

PUBLISHED

Description

Qualys discovered that needrestart, before version 3.8, allows local attackers to execute arbitrary code as root by tricking needrestart into running the Ruby interpreter with an attacker-controlled RUBYLIB environment variable.