https://seclists.org/oss-sec/2024/q1/257: CVE-2024-28085: Escape sequence injection in util-linux wall
Published Mar 27, 2024
·Updated
Affected Software
1 affected component
util-linux wall
Frequently Asked Questions
1
What is CVE-2024-28085?
CVE-2024-28085 is a vulnerability in the util-linux wall tool that allows for escape sequence injection, potentially leading to unprivileged code execution.
2
What is the severity of CVE-2024-28085?
The severity of CVE-2024-28085 is high due to the potential impact on system security through unauthorized command execution.
3
How do I fix CVE-2024-28085?
To fix CVE-2024-28085, you should update the util-linux package to the latest version where the vulnerability has been patched.
4
What systems are affected by CVE-2024-28085?
CVE-2024-28085 affects systems utilizing the util-linux wall tool, commonly found in many Unix-like operating systems.
5
How can I mitigate the risks associated with CVE-2024-28085?
To mitigate the risks of CVE-2024-28085, restrict permissions for the wall command and ensure users are aware of safe usage practices.