CVE-2024-11003

Updated: 2025-11-10 02:42:34.806407

Description:

Qualys discovered that needrestart, before version 3.8, passes unsanitized data to a library (Modules::ScanDeps) which expects safe input. This could allow a local attacker to execute arbitrary shell commands. Please see the related CVE-2024-10224 in Modules::ScanDeps.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x 0.0
CVSS Version 3.x 0.0

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

Debian 10 ELS needrestart 3.4.0 0.0 Already Fixed 2025-11-07 23:16:50
Ubuntu 16.04 ELS needrestart 2.6 0.0 Released CLSA-2024:1734028058 2024-12-12 16:23:34
Ubuntu 18.04 ELS needrestart 3.1 0.0 Released CLSA-2024:1733246466 2024-12-03 13:22:03