USN-7117-1: needrestart and Module::ScanDeps vulnerabilities
Qualys discovered that needrestart passed unsanitized data to a library (libmodule-scandeps-perl) which expects safe input. A local attacker could possibly use this issue to execute arbitrary code as root. (CVE-2024-11003) Qualys discovered that the library libmodule-scandeps-perl incorrectly parsed perl code. This could allow a local attacker to execute arbitrary shell commands. (CVE-2024-10224) Qualys discovered that needrestart incorrectly used the PYTHONPATH environment variable to spawn a new Python interpreter. A local attacker could possibly use this issue to execute arbitrary code as root. (CVE-2024-48990) Qualys discovered that needrestart incorrectly checked the path to the Python interpreter. A local attacker could possibly use this issue to win a race condition and execute arbitrary code as root. (CVE-2024-48991) Qualys discovered that needrestart incorrectly used the RUBYLIB environment variable to spawn a new Ruby interpreter. A local attacker could possibly use this issue to execute arbitrary code as root. (CVE-2024-48992)
Affected Software
Event History
Child vulnerabilities
Contains the following vulnerabilities.
Frequently Asked Questions
What is the severity of USN-7117-1?
The severity of USN-7117-1 is considered critical due to the potential for local attackers to execute arbitrary code as root.
How do I fix USN-7117-1?
To fix USN-7117-1, update the affected packages to the recommended versions specified in the advisory.
Which software packages are affected by USN-7117-1?
The affected packages include libmodule-scandeps-perl and needrestart on specific Ubuntu versions.
What is the risk of not addressing USN-7117-1?
Not addressing USN-7117-1 poses a significant risk as it allows local attackers to execute arbitrary code with root privileges.
When was the vulnerability USN-7117-1 discovered?
The vulnerability USN-7117-1 was discovered by Qualys and reported in 2024.