Executive Summary

Informations
Name CVE-2024-52336 First vendor Publication 2024-11-26
Vendor Cve Last vendor Modification 2025-02-03

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector :
Cvss Base Score N/A Attack Range N/A
Cvss Impact Score N/A Attack Complexity N/A
Cvss Expoit Score N/A Authentication N/A
Calculate full CVSS 2.0 Vectors scores

Detail

A script injection vulnerability was identified in the Tuned package. The `instance_create()` D-Bus function can be called by locally logged-in users without authentication. This flaw allows a local non-privileged user to execute a D-Bus call with `script_pre` or `script_post` options that permit arbitrary scripts with their absolute paths to be passed. These user or attacker-controlled executable scripts or programs could then be executed by Tuned with root privileges that could allow attackers to local privilege escalation.

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-52336

Sources (Detail)

https://access.redhat.com/errata/RHSA-2024:10384
https://access.redhat.com/errata/RHSA-2025:0879
https://access.redhat.com/errata/RHSA-2025:0880
https://access.redhat.com/security/cve/CVE-2024-52336
https://bugzilla.redhat.com/show_bug.cgi?id=2324540
https://security.opensuse.org/2024/11/26/tuned-instance-create.html
https://www.openwall.com/lists/oss-security/2024/11/28/1
https://www.openwall.com/lists/oss-security/2024/11/28/2
Source Url

Alert History

If you want to see full details history, please login or register.
0
1
2
3
4
5
6
Date Informations
2025-02-04 00:20:48
  • Multiple Updates
2024-12-31 14:03:44
  • Multiple Updates
2024-12-05 17:20:30
  • Multiple Updates
2024-12-02 17:20:30
  • Multiple Updates
2024-11-29 09:22:17
  • Multiple Updates
2024-11-27 00:22:51
  • Multiple Updates
2024-11-26 21:22:52
  • First insertion