INFSA-2024:6986: nano security update
Information about definition
Identificator: INFSA-2024:6986
Type: security
Release date: 2024-10-10 10:40:59 UTC
Information about package
GNU nano is a small and friendly text editor.
Vulnerabilities description
- CVE-2024-5742
A vulnerability was found in GNU Nano that allows a possible privilege escalation through an insecure temporary file. If Nano is killed while editing, a file it saves to an emergency file with the permissions of the running user provides a window of opportunity for attackers to escalate privileges through a malicious symlink.
Severity level
CVE | Score CVSS 2.0 | Score CVSS 3.x | Score CVSS 4.0 |
---|---|---|---|
NIST — CVE-2024-5742
|
no information | 4.7 | no information |
Updated packages