A vulnerability was found in GNU Nano that allows a possible privilege escalation through an insecure temporary file. If Nano is killed while editing, a file it saves to an emergency file with the permissions of the running user provides a window of opportunity for attackers to escalate privileges through a malicious symlink. (CVE-2024-5742) . MGASA-2024-0223 - Updated nano packages fix security vulnerability Publication date: 15 Jun 2024 URL: https://advisories.mageia.org/MGASA-2024-0223.html Type: security Affected Mageia releases: 9 CVE: CVE-2024-5742 A vulnerability was found in GNU Nano that allows a possible privilege escalation through an insecure temporary file. If Nano is killed while editing, a file it saves to an emergency file with the permissions of the running user provides a window of opportunity for attackers to escalate privileges through a malicious symlink. (CVE-2024-5742) References: - https://bugs.mageia.org/show_bug.cgi?id=33297 - - https://www.cve.org/CVERecord?id=CVE-2024-5742 SRPMS: - 9/core/nano-7.2-1.1.mga9 . Recent updates to Nano packages fix serious privilege escalation flaws linked to unsafe temporary file handling, urging users to apply patches and enhance file security. Mageia 9, Nano Security Advisory, Privilege Escalation, Malicious Symlink. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.