CVE-2008-1926

CWE-94Code Injection7 documents7 sources
Severity
7.5HIGH
EPSS
1.8%
top 17.33%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 24
Latest updateMay 1

Description

Argument injection vulnerability in login (login-utils/login.c) in util-linux-ng 2.14 and earlier makes it easier for remote attackers to hide activities by modifying portions of log events, as demonstrated by appending an "addr=" statement to the login name, aka "audit log injection."

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages2 packages

Debianutil-linux< 2.13.1.1-1+3
NVDlinux/util-linux5 versions+4

🔴Vulnerability Details

3
GHSA
GHSA-xj37-vmc7-9w35: Argument injection vulnerability in login (login-utils/login2022-05-01
OSV
CVE-2008-1926: Argument injection vulnerability in login (login-utils/login2008-04-24
CVEList
CVE-2008-1926: Argument injection vulnerability in login (login-utils/login2008-04-23

📋Vendor Advisories

2
Red Hat
util-linux: audit log injection via login2008-04-21
Debian
CVE-2008-1926: util-linux - Argument injection vulnerability in login (login-utils/login.c) in util-linux-ng...2008

💬Community

1
Bugzilla
CVE-2008-1926 util-linux: audit log injection via login2008-04-24