Tag: Ubuntu’s Needrestart Package

Decades-Old Security Vulnerabilities Found in Ubuntu’s Needrestart Package
News

Decades-Old Security Vulnerabilities Found in Ubuntu’s Needrestart Package

A local attacker might obtain root access without any user involvement because to several ten-year-old security flaws in the needrestart package, which is installed by default in Ubuntu Server (from version 21.04). The vulnerabilities are easy to exploit, therefore users must act fast to apply the remedies, according to the Qualys Threat Research Unit (TRU), which discovered and disclosed them early last month. It is thought that the vulnerabilities have existed since needrestart 0.8, which was made available on April 27, 2014, when interpreter support was added. Ubuntu stated in an advisory that these needrestart exploits have been fixed in version 3.8 and that they permit Local Privilege Escalation (LPE), which enables a local attacker to obtain root privileges read more about Dec...