First published: Wed Apr 23 2008(Updated: )
Argument injection vulnerability in login (login-utils/login.c) in util-linux-ng 2.14 and earlier makes it easier for remote attackers to hide activities by modifying portions of log events, as demonstrated by appending an "addr=" statement to the login name, aka "audit log injection."
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Linux util-linux | =2.13 | |
Linux util-linux | =2.13.0.1 | |
Linux util-linux | =2.13.1 | |
Linux util-linux | =2.13.1.1 | |
Linux util-linux | =2.14-rc1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.