Logo
vulnerabilityCVE-2024-5742
Name
CVE-2024-5742
Source
NVD ( link)Debian ( link)
Description
A vulnerability was found in GNU Nano that allows a possible privilege escalation through an insecure temporary file. If Nano is killed while editing, a file it saves to an emergency file with the permissions of the running user provides a window of opportunity for attackers to escalate privileges through a malicious symlink.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
nano
Exploitable

Vulnerability Ratings#


6.7
CVSSv31
6.7
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
openwrt
master
9.0-r1
Not Affected
openwrt
openwrt-25.12
9.0-r1
Not Affected
yocto
kirkstone
6.2
Exploitable
yocto
master
9.0
Not Affected