ZeroHour

CVE-2024-48992

CVSS 3.1
7.8 high
EPSS
8%p94
Published
()
Modified
Description

Qualys discovered that needrestart, before version 3.8, allows local attackers to execute arbitrary code as root by tricking needrestart into running the Ruby interpreter with an attacker-controlled RUBYLIB environment variable.

Vendors
needrestart project
Products
needrestart
Weakness
CWE-427
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news