UNIX symbolic link following in nano - CVE-2024-5742
Published: June 25, 2024
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a symlink following issue. A local user can create a specially crafted symbolic link to a critical file on the system and overwrite it with privileges of the application.
Successful exploitation of this vulnerability may result in privilege escalation.
Affected software
Oracle Linux
Red Hat Enterprise Linux for x86_64
Anolis OS
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Ubuntu
openEuler
SmartFabric Storage Software
LANTIME Operating System Firmware (LTOS)
RecoverPoint for Virtual Machines
nano (Ubuntu package)
nano-doc
nano
nano (Red Hat package)
nano-help
nano-debugsource
nano-debuginfo
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM QRadar Network Packet Capture
How to mitigate CVE-2024-5742
SmartFabric Storage Software - update to 1.4.3
RecoverPoint for Virtual Machines - update to 6.0 SP2 P1
LANTIME Operating System Firmware (LTOS) - update to 7.08.018
nano (Ubuntu package) - addressed in versions Ubuntu Pro, 4.8-1ubuntu1.1, 6.2-1ubuntu0.1, 7.2-2ubuntu0.1
nano-doc - update to 2.9.8-2.0.1
nano - addressed in versions 2.9.8-2.0.1, 8.0-1
nano (Red Hat package) - addressed in versions 2.9.8-3.el8_10, 5.6.1-6.el9
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.8.8
IBM QRadar Network Packet Capture - update to 7.5.0 Update Package 11
nano-help - update to 8.0-1
nano-debugsource - update to 8.0-1
nano-debuginfo - update to 8.0-1
nano - update to 8.0-1
External References
Related Security Bulletins
- Privilege escalation in GNU Nano
- openEuler update for nano
- Red Hat Enterprise Linux 8 update for nano
- Ubuntu update for nano
- Multiple vulnerabilities in Oracle Linux
- Ubuntu update for nano
- Red Hat Enterprise Linux 9 update for nano
- Multiple vulnerabilities in IBM Watson Speech Services Cartridge
- Multiple vulnerabilities in IBM QRadar Network Packet Capture
- Anolis OS update for nano
- Anolis OS update for nano
- Dell SmartFabric Storage Software update for third-party components
- Meinberg LANTIME firmware update for third-party components (December 2024)
- Dell RecoverPoint for Virtual Machines update for third-party components