Bug 2271942 (CVE-2024-28085) - CVE-2024-28085 util-linux: CVE-2024-28085: wall: escape sequence injection
Summary: CVE-2024-28085 util-linux: CVE-2024-28085: wall: escape sequence injection
Keywords:
Status: CLOSED NOTABUG
Alias: CVE-2024-28085
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks: 2271943
TreeView+ depends on / blocked
 
Reported: 2024-03-27 19:43 UTC by Marco Benatto
Modified: 2024-03-27 19:48 UTC (History)
0 users

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2024-03-27 19:48:49 UTC
Embargoed:


Attachments (Terms of Use)

Description Marco Benatto 2024-03-27 19:43:26 UTC
wall in util-linux through 2.40, often installed with setgid tty permissions, allows escape sequences to be sent to other users' terminals through argv. (Specifically, escape sequences received from stdin are blocked, but escape sequences received from argv are not blocked.) There may be plausible scenarios where this leads to account takeover.


Note You need to log in before you can comment on or make changes to this bug.