All errata/c10f1/ALT-PU-2024-14552-3
ALT-PU-2024-14552-3

Package update nano in branch c10f1

Version8.0-alt1
Published2024-10-24
Max severityMEDIUM
Severity:

Closed issues (2)

BDU:2024-06879
MEDIUM4.7

Уязвимость текстового редактора Nano, связанная с ошибками обработки временных файлов, позволяющая нарушителю оказать воздействие на целостность данных

Published: 2024-09-13Modified: 2026-01-20
CVSS 3.xMEDIUM 4.7
CVSS:3.x/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N
CVSS 2.0LOW 3.8
CVSS:2.0/AV:L/AC:H/Au:S/C:N/I:C/A:N
References
CVE-2024-5742
MEDIUM6.7

A vulnerability was found in GNU Nano that allows a possible privilege escalation through an insecure temporary file. If Nano is killed while editing, a file it saves to an emergency file with the permissions of the running user provides a window of opportunity for attackers to escalate privileges through a malicious symlink.

Published: 2024-06-12Modified: 2024-11-21
CVSS 3.xMEDIUM 6.7
CVSS:3.x/CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H

Closed bugs (1)

Прошу обновить пакет nano до версии 8.0