216.73.217.80

CVE-2024-38531

· Published 28/06/2024 14:15 · Modified 28/06/2024 14:15

Labels: CVE-2024-38531 2024-06-28CVE-2024-38531CWE-278[email protected]

Essential information

Published
28/06/2024 14:15
Modified
28/06/2024 14:15
Author
Creator
CVSS
3.6 LOW (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L

CVSS metrics

Description

Nix is a package manager for Linux and other Unix systems that makes package management reliable and reproducible. A build process has access to and can change the permissions of the build directory. After creating a setuid binary in a globally accessible location, a malicious local user can assume the permissions of a Nix daemon worker and hijack all future builds. This issue was patched in version(s) 2.23.1, 2.22.2, 2.21.3, 2.20.7, 2.19.5 and 2.18.4.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

References