CVE-2024-48990
41Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendcvss 7.8epss 20%
from disclosure to weapon0 days
Published on NVDNov 19
metasploitNov 19
exploitation probability
20%top 3% of all CVEs
observed exploitation
nono source reports it
Qualys discovered that needrestart, before version 3.8, allows local attackers to execute arbitrary code as root by tricking needrestart into running the Python interpreter with an attacker-controlled PYTHONPATH environment variable.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products
needrestart · needrestartReferences
http://seclists.org/fulldisclosure/2024/Nov/17https://github.com/liske/needrestart/commit/fcc9a4401392231bef4ef5ed026a0d7a275149abhttps://lists.debian.org/debian-lts-announce/2024/11/msg00014.htmlhttps://www.cve.org/CVERecord?id=CVE-2024-48990https://www.openwall.com/lists/oss-security/2024/11/19/1https://www.qualys.com/2024/11/19/needrestart/needrestart.txt