Ubuntu元件Needrestart存在漏洞,攻擊者有機會藉此得到root權限
支付動態 · 2024-11-21

研究人員針對Ubuntu伺服器版預載公用程式Needrestart的漏洞提出警告,指出由於21.04版作業系統預設安裝這項元件,影響範圍將有可能相當廣泛,呼籲IT人員應儘速處理

資安業者Qualys指出,伺服器版Ubuntu預載的公用程式Needrestart存在5項本機權限提升(LPE)漏洞,未獲取足夠權限的攻擊者,可藉此得到完整的root存取權限,過程裡無需使用者互動。研究人員強調,利用這些漏洞相當容易,很快就可能會有人將其用於實際攻擊。

這些漏洞分別是CVE-2024-10224、CVE-2024-11003、CVE-2024-48990、CVE-2024-48991、CVE-2024-48992,CVSS風險評為5.3至7.8分。附帶一提的是,這些漏洞從2014年4月發布的0.8版就存在,換言之,已存在超過10年。對此,開發者接獲通報後,推出3.8版修補。

什麼是Needrestart?這項公用程式會偵測系統是否有需要重新啟動的服務,之所以需要進行這項作業的原因,在於更新共用程式庫的過程中,Needrestart會察覺服務仍在使用舊版檔案,自動將其重新啟動,作業系統無需為此關機、重新啟動。自21.04版Ubuntu Server開始,Needrestart成為預設安裝的元件,因此這些弱點的影響範圍,有可能會相當廣泛。

若是IT人員無法及時更新這項元件,Qualys提出臨時緩解措施,那就是調整Needrestart的組態檔案,停用啟發式解譯器的功能。

Popular articles
Vietnam's tightening online gaming policy creates new market opportunities
Southeast Asia
British gambling levy rates confirmed for each vertical
Regulation
UK MPs reopen 2025 gambling inquiry as reform stalls
Regulation
Gaming & Technology Expo Makes a Powerful Entrance in CDMX
Marketing
Super PAC Raises $48 Million: Sports Betting Forces Ramp Up Political Push
Regulation
Online gambling, crypto pose ongoing money laundering risks in Philippines, analyst says
Southeast Asia
Institutional Academy that exceeded expectations marked the opening of GAT CDMX
Online Game
B2B Tech Infrastructure Gains Momentum in Philippine Gaming Sector
Southeast Asia
SBC Summit Canada to Make Player Safety a Key Pillar of 2026 Agenda
Marketing
Full House at GAT Expo Cartagena 2026 Academic Agenda
Online Game
New Jersey July Gambling Revenue Hits $606M, Sweeps Casinos Banned
Regulation
Kazakhstan plans to penalise online casino promotions
Regulation
GAT Expo Puerto Rico Will Pulse with the New Era of Gaming in the Caribbean
Marketing
Are you ready to maximize your earnings? Try ProPush.me Constructor!
Marketing
HUIDU Invites You to Booth T70 at iGB L!VE 2026 — Let’s Ignite London This July!
HUIDU Focus
Home
Game
Cooperation
Find
My