Input validation error in needrestart - CVE-2022-30688
Published: May 18, 2022
Vulnerability identifier: #VU63356
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-30688
CWE-ID: CWE-20
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to execute arbitrary code with elevated privileges.
The vulnerability exists due to application uses incorrect regexes to detect Perl, Python, and Ruby interpreters. A local user can pass specially crafted data to the application and execute arbitrary code with elevated privileges.
Affected software
needrestart
Fedora
Ubuntu
needrestart (Ubuntu package)
needrestart (Debian package)
needrestart
Fedora
Ubuntu
needrestart (Ubuntu package)
needrestart (Debian package)
needrestart
How to mitigate CVE-2022-30688
Install updates from vendor's website.
needrestart - update to 3.6
needrestart (Ubuntu package) - addressed in versions 3.1-1ubuntu0.1, 3.4-6ubuntu0.1, 3.5-4ubuntu2.1, 3.5-5ubuntu2.1
needrestart (Debian package) - addressed in versions 3.4-5+deb10u1, 3.5-4+deb11u1
needrestart - addressed in versions 3.6-3.el7, 3.6-3.el8
needrestart (Ubuntu package) - addressed in versions 3.1-1ubuntu0.1, 3.4-6ubuntu0.1, 3.5-4ubuntu2.1, 3.5-5ubuntu2.1
needrestart (Debian package) - addressed in versions 3.4-5+deb10u1, 3.5-4+deb11u1
needrestart - addressed in versions 3.6-3.el7, 3.6-3.el8