https://seclists.org/oss-sec/2024/q1/261: CVE-2024-28085: Escape sequence injection in util-linux wall
Published Mar 27, 2024
·Updated
Affected Software
1 affected component
util-linux util-linux
Frequently Asked Questions
1
What is the severity of CVE-2024-28085?
CVE-2024-28085 is classified as a medium-severity vulnerability due to its potential for escape sequence injection.
2
How do I fix CVE-2024-28085?
To remediate CVE-2024-28085, it is recommended to update util-linux to the latest version where the vulnerability has been patched.
3
What impact does CVE-2024-28085 have on systems running util-linux?
CVE-2024-28085 can allow an attacker to execute arbitrary commands through crafted message input, potentially compromising the system's integrity.
4
Is CVE-2024-28085 present in all versions of util-linux?
CVE-2024-28085 affects multiple versions of util-linux prior to the fix being applied, so checking the version is crucial for vulnerability assessment.
5
Who is affected by CVE-2024-28085?
Users and administrators of systems running vulnerable versions of util-linux are at risk from CVE-2024-28085.