Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xj37-vmc7-9w35

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Argument injection vulnerability in login (login-utils/login.c) in util-linux-ng 2.14 and earlier makes it easier for remote attackers to hide activities by modifying portions of log events, as demonstrated by appending an "addr=" statement to the login name, aka "audit log injection."

Argument injection vulnerability in login (login-utils/login.c) in util-linux-ng 2.14 and earlier makes it easier for remote attackers to hide activities by modifying portions of log events, as demonstrated by appending an "addr=" statement to the login name, aka "audit log injection."

Ссылки

EPSS

Процентиль: 82%
0.01774
Низкий

Дефекты

CWE-94

Связанные уязвимости

ubuntu
больше 17 лет назад

Argument injection vulnerability in login (login-utils/login.c) in util-linux-ng 2.14 and earlier makes it easier for remote attackers to hide activities by modifying portions of log events, as demonstrated by appending an "addr=" statement to the login name, aka "audit log injection."

redhat
больше 17 лет назад

Argument injection vulnerability in login (login-utils/login.c) in util-linux-ng 2.14 and earlier makes it easier for remote attackers to hide activities by modifying portions of log events, as demonstrated by appending an "addr=" statement to the login name, aka "audit log injection."

nvd
больше 17 лет назад

Argument injection vulnerability in login (login-utils/login.c) in util-linux-ng 2.14 and earlier makes it easier for remote attackers to hide activities by modifying portions of log events, as demonstrated by appending an "addr=" statement to the login name, aka "audit log injection."

debian
больше 17 лет назад

Argument injection vulnerability in login (login-utils/login.c) in uti ...

EPSS

Процентиль: 82%
0.01774
Низкий

Дефекты

CWE-94