util-linux: CVE-2024-28085: wall: escape sequence injection
Published Mar 27, 2024
4.4
MEDIUMCVSS 3.1
EPSS 2.24%
Description
wall in util-linux through 2.40, often installed with setgid tty permissions, allows escape sequences to be sent to other users' terminals through argv. (Specifically, escape sequences received from stdin are blocked, but escape sequences received from argv are not blocked.) There may be plausible scenarios where this leads to account takeover.
Affected products
No data.
Configuration 1
- ≥ 2.24 · < 2.39.4
Configuration 2
- 10.0
-
Affected
- ≥ 0, ≤ 2.40
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Kernel | Util-Linux | unknown | Affected
|
Red Hat Enterprise Linux 10
util-linux
Not affected
Red Hat Enterprise Linux 6
util-linux-ng
Not affected
Red Hat Enterprise Linux 7
util-linux
Not affected
Red Hat Enterprise Linux 8
util-linux
Not affected
Red Hat Enterprise Linux 9
util-linux
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | util-linux | Not affected | n/a |
| Red Hat Enterprise Linux 6 | util-linux-ng | Not affected | n/a |
| Red Hat Enterprise Linux 7 | util-linux | Not affected | n/a |
| Red Hat Enterprise Linux 8 | util-linux | Not affected | n/a |
| Red Hat Enterprise Linux 9 | util-linux | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This vulnerability doesn't affect any supported Red Hat products. The mesg and wall programs are installed without setgid permissions, which prevents exploitation.
References (23)
- http://seclists.org/fulldisclosure/2024/Mar/35
- http://www.openwall.com/lists/oss-security/2024/03/27/5 mailing-listExploitMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2024/03/27/6 mailing-listMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2024/03/27/7 mailing-listMailing ListPatchThird Party Advisory
- http://www.openwall.com/lists/oss-security/2024/03/27/8 mailing-listMailing ListPatchThird Party Advisory
- http://www.openwall.com/lists/oss-security/2024/03/27/9 mailing-listMailing ListPatchThird Party Advisory
- http://www.openwall.com/lists/oss-security/2024/03/28/1 mailing-listMailing ListPatchThird Party Advisory
- http://www.openwall.com/lists/oss-security/2024/03/28/2 mailing-listMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2024/03/28/3 mailing-listMailing ListPatchThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2024-28085 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2271942 Issue Tracking
- https://cert-portal.siemens.com/productcert/html/ssa-082556.html
- https://cert-portal.siemens.com/productcert/html/ssa-202008.html
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-25252 Advisory
- https://github.com/skyler-ferrante/CVE-2024-28085 ExploitThird Party Advisory
- https://github.com/util-linux/util-linux/security/advisories/GHSA-xv2h-c6ww-mrjq Broken Link
- https://lists.debian.org/debian-lts-announce/2024/04/msg00005.html mailing-listMailing ListThird Party Advisory
- https://mirrors.edge.kernel.org/pub/linux/utils/util-linux/ Product
- https://nvd.nist.gov/vuln/detail/CVE-2024-28085
- https://people.rit.edu/sjf5462/6831711781/wall_2_27_2024.txt ExploitThird Party Advisory
- https://security.netapp.com/advisory/ntap-20240531-0003/ Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2024-28085
- https://www.openwall.com/lists/oss-security/2024/03/27/5 Mailing ListThird Party Advisory
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
GitHub
No data