A vulnerability was found in GNU Nano that allows a possible privilege
escalation through an insecure temporary file. If Nano is killed while
editing, a file it saves to an emergency file with the permissions of
the running user provides a window of opportunity for attackers to
escalate privileges through a malicious symlink. (CVE-2024-5742)
- https://bugs.mageia.org/show_bug.cgi?id=33297
-
- https://www.cve.org/CVERecord?id=CVE-2024-5742
- 9/core/nano-7.2-1.1.mga9
Get the latest Linux and open source security news straight to your inbox.