RHSA-2024:6986: Low: nano security update
GNU nano is a small and friendly text editor.Security Fix(es): nano: running chmod and chown on the filename allows malicious user to replace the emergency file with a malicious symlink to a root-owned file (CVE-2024-5742) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/nanoto a version that resolves this vulnerability.Fixed in 2.9.8-3.el8_10 - Upgrade
Upgrade
redhat/nano-debuginfoto a version that resolves this vulnerability.Fixed in 2.9.8-3.el8_10 - Upgrade
Upgrade
redhat/nano-debugsourceto a version that resolves this vulnerability.Fixed in 2.9.8-3.el8_10 - Upgrade
Upgrade
redhat/nanoto a version that resolves this vulnerability.Fixed in 2.9.8-3.el8_10.aa - Upgrade
Upgrade
redhat/nano-debuginfoto a version that resolves this vulnerability.Fixed in 2.9.8-3.el8_10.aa - Upgrade
Upgrade
redhat/nano-debugsourceto a version that resolves this vulnerability.Fixed in 2.9.8-3.el8_10.aa
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:6986?
The severity of RHSA-2024:6986 is classified as low.
How do I fix RHSA-2024:6986?
To fix RHSA-2024:6986, update the nano package to version 2.9.8-3.el8_10 or later.
What vulnerability is addressed by RHSA-2024:6986?
RHSA-2024:6986 addresses a vulnerability where malicious users could exploit permissions on emergency files, allowing potential symlink attacks.
Which systems are affected by RHSA-2024:6986?
RHSA-2024:6986 affects various architectures of Red Hat Enterprise Linux such as x86_64, ARM 64, Power, and IBM z Systems.
Is there a known exploit for RHSA-2024:6986?
As of now, there is no public information indicating a known exploit specifically for RHSA-2024:6986.