Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

Mageia 9 MGASA-2024-0223 Moderate: Nano Privilege Escalation Risk

mageia
Calendar Grey June 15, 2024
Dist Mageia Esm H88
Recent updates to Nano packages fix serious privilege escalation flaws linked to unsafe temporary file handling, urging users to apply patches and enhance file security
A vulnerability was found in GNU Nano that allows a possible privilege escalation through an insecure temporary file

Summary

A vulnerability was found in GNU Nano that allows a possible privilege escalation through an insecure temporary file. If Nano is killed while editing, a file it saves to an emergency file with the permissions of the running user provides a window of opportunity for attackers to escalate privileges through a malicious symlink. (CVE-2024-5742)

References

- https://bugs.mageia.org/show_bug.cgi?id=33297

-

- https://www.cve.org/CVERecord?id=CVE-2024-5742

Resolution

SRPMS

- 9/core/nano-7.2-1.1.mga9

Publication date: 15 Jun 2024
URL: https://advisories.mageia.org/MGASA-2024-0223.html
Type: security
CVE: CVE-2024-5742

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here