CVE-2024-11003: OS Command Injection
Last updated 20 November 2024
Other sources
Qualys discovered that needrestart, before version 3.8, passes unsanitized data to a library (Modules::ScanDeps) which expects safe input. This could allow a local attacker to execute arbitrary shell commands. Please see the related CVE-2024-10224 in Modules::ScanDeps.
— NVD
This CVE was automatically created from a reference found in an email or other text. If you are reading this, then this CVE entry is probably erroneous, since this text should be replaced by the official CVE description automatically.
— Launchpad
Affected Software
Remediation
Mitigation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-11003?
CVE-2024-11003 is considered a high severity vulnerability due to its potential for local attackers to execute arbitrary shell commands.
How do I fix CVE-2024-11003?
To fix CVE-2024-11003, upgrade to needrestart version 3.8 or above.
What versions of needrestart are affected by CVE-2024-11003?
CVE-2024-11003 affects needrestart versions prior to 3.8, specifically 3.5-4+deb11u3, 3.6-4+deb12u1, and 3.7-3.1.
Who discovered CVE-2024-11003?
CVE-2024-11003 was discovered by the security firm Qualys.
What types of attacks can CVE-2024-11003 enable?
CVE-2024-11003 can enable local attackers to execute arbitrary shell commands through unsanitized input.