Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-28085

Опубликовано: 27 мар. 2024
Источник: redhat
CVSS3: 4.4
EPSS Средний

Описание

wall in util-linux through 2.40, often installed with setgid tty permissions, allows escape sequences to be sent to other users' terminals through argv. (Specifically, escape sequences received from stdin are blocked, but escape sequences received from argv are not blocked.) There may be plausible scenarios where this leads to account takeover.

Отчет

This vulnerability doesn't affect any supported Red Hat products. The mesg and wall programs are installed without setgid permissions, which prevents exploitation.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6util-linux-ngNot affected
Red Hat Enterprise Linux 7util-linuxNot affected
Red Hat Enterprise Linux 8util-linuxNot affected
Red Hat Enterprise Linux 9util-linuxNot affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-268
https://bugzilla.redhat.com/show_bug.cgi?id=2271942util-linux: CVE-2024-28085: wall: escape sequence injection

EPSS

Процентиль: 93%
0.1148
Средний

4.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 3.3
ubuntu
около 1 года назад

wall in util-linux through 2.40, often installed with setgid tty permissions, allows escape sequences to be sent to other users' terminals through argv. (Specifically, escape sequences received from stdin are blocked, but escape sequences received from argv are not blocked.) There may be plausible scenarios where this leads to account takeover.

CVSS3: 3.3
nvd
около 1 года назад

wall in util-linux through 2.40, often installed with setgid tty permissions, allows escape sequences to be sent to other users' terminals through argv. (Specifically, escape sequences received from stdin are blocked, but escape sequences received from argv are not blocked.) There may be plausible scenarios where this leads to account takeover.

CVSS3: 3.3
msrc
9 месяцев назад

Описание отсутствует

CVSS3: 3.3
debian
около 1 года назад

wall in util-linux through 2.40, often installed with setgid tty permi ...

suse-cvrf
около 1 года назад

Security update for util-linux

EPSS

Процентиль: 93%
0.1148
Средний

4.4 Medium

CVSS3