| Summary: | nano new security issue CVE-2024-5742 | ||
|---|---|---|---|
| Product: | Mageia | Reporter: | Nicolas Salguero <nicolas.salguero> |
| Component: | Security | Assignee: | QA Team <qa-bugs> |
| Status: | RESOLVED FIXED | QA Contact: | Sec team <security> |
| Severity: | normal | ||
| Priority: | Normal | CC: | andrewsfarm, fri, herman.viaene, sysadmin-bugs |
| Version: | 9 | Keywords: | advisory, validated_update |
| Target Milestone: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | MGA9-64-OK | ||
| Source RPM: | nano-7.2-1.mga9.src.rpm | CVE: | CVE-2024-5742 |
| Status comment: | |||
|
Description
Nicolas Salguero
2024-06-12 15:25:59 CEST
Nicolas Salguero
2024-06-12 15:26:37 CEST
Source RPM:
(none) =>
nano-7.2-2.mga10.src.rpm Suggested advisory: ======================== The updated package fixes a security vulnerability: A vulnerability was found in GNU Nano that allows a possible privilege escalation through an insecure temporary file. If Nano is killed while editing, a file it saves to an emergency file with the permissions of the running user provides a window of opportunity for attackers to escalate privileges through a malicious symlink. (CVE-2024-5742) References: https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/VCJGQ6SCOSZGXAPYA7GYUT3M6ZPBLO5V/ ======================== Updated package in core/updates_testing: ======================== nano-7.2-1.1.mga9 from SRPM: nano-7.2-1.1.mga9.src.rpm Whiteboard:
MGA9TOO =>
(none)
katnatek
2024-06-13 19:37:14 CEST
Keywords:
(none) =>
advisory mga9-64 OK running in Plasma X11 Konsole created file, saved, restart, open edit, etc. CC:
(none) =>
fri Not like that I try to reproduce the fail with current version but killing nano not produce the emergency file The application update without issue And works CC:
(none) =>
andrewsfarm MGA9-64 Plasma Wayland on HP-Pavillion No installation issues. Tried to use it, found it even clumsier than vi. Anyway, did some operations on a text file, found rather accidentally that mouse operation could be set-reset. Probably due to this being a slow machine, closing nano left the mouse cursor with the icon to resize a window wherever I moved it. After a while, it returned to normal operation. In view of other tests above, good to go. CC:
(none) =>
herman.viaene Validating. CC:
(none) =>
sysadmin-bugs An update for this issue has been pushed to the Mageia Updates repository. https://advisories.mageia.org/MGASA-2024-0223.html Resolution:
(none) =>
FIXED |