cbcvebase.
CVE-2024-5742
published 2024-06-12

CVE-2024-5742: A vulnerability was found in GNU Nano that allows a possible privilege escalation through an insecure temporary file. If Nano is killed while editing, a file…

medium6.7CVSS 3.1
AVLACHPRLUIRSUCHIHAH
A vulnerability was found in GNU Nano that allows a possible privilege escalation through an insecure temporary file. If Nano is killed while editing, a file it saves to an emergency file with the permissions of the running user provides a window of opportunity for attackers to escalate privileges through a malicious symlink.

Affected

16 ranges
VendorProductVersion rangeFixed in
debiannano< nano 7.2-1+deb12u1 (bookworm)nano 7.2-1+deb12u1 (bookworm)
gnunano>= 0 < 5.4-2+deb11u35.4-2+deb11u3
gnunano>= 0 < 7.2-1+deb12u17.2-1+deb12u1
gnunano>= 0 < 8.0-18.0-1
gnunano>= 0 < 8.0-18.0-1
gnunano>= 2.2.0 < 8.08.0
msrcazl3_nano_6.4-2_on_azure_linux_3.0
msrcazure_linux_3.0_arm
msrcazure_linux_3.0_x64
msrccbl2_nano_6.0-3_on_cbl_mariner_2.0
msrccbl_mariner_2.0_arm
msrccbl_mariner_2.0_x64
redhatenterprise_linux
redhatenterprise_linux
redhatenterprise_linux
redhatenterprise_linux

CVSS provenance

nvdv3.16.7MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
osv6.7MEDIUM