cbcvebase.
CVE-2024-28085
published 2024-03-27

CVE-2024-28085: wall in util-linux through 2.40, often installed with setgid tty permissions, allows escape sequences to be sent to other users' terminals through argv…

low3.3CVSS 3.1
AVLACLPRLUINSUCNILAN
wall in util-linux through 2.40, often installed with setgid tty permissions, allows escape sequences to be sent to other users' terminals through argv. (Specifically, escape sequences received from stdin are blocked, but escape sequences received from argv are not blocked.) There may be plausible scenarios where this leads to account takeover.

Affected

13 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianutil-linux< util-linux 2.38.1-5+deb12u1 (bookworm)util-linux 2.38.1-5+deb12u1 (bookworm)
kernelutil-linux>= 0 < 2.36.1-8+deb11u22.36.1-8+deb11u2
kernelutil-linux>= 0 < 2.38.1-5+deb12u12.38.1-5+deb12u1
kernelutil-linux>= 0 < 2.39.3-112.39.3-11
kernelutil-linux>= 0 < 2.39.3-112.39.3-11
kernelutil-linux>= 2.24 < 2.39.42.39.4
msrcazl3_util-linux_2.39.2-2_on_azure_linux_3.0
msrcazure_linux_3.0_arm
msrcazure_linux_3.0_x64
msrccbl2_util-linux_2.37.4-9_on_cbl_mariner_2.0
msrccbl_mariner_2.0_arm
msrccbl_mariner_2.0_x64

CVSS provenance

nvdv3.13.3LOWCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
osv3.3LOW