https://seclists.org/oss-sec/2024/q1/263: Re: CVE-2024-28085: Escape sequence injection in util-linux wall
Published Mar 28, 2024
·Updated
Affected Software
1 affected component
util-linux wall
Frequently Asked Questions
1
What is the severity of CVE-2024-28085?
CVE-2024-28085 has a medium severity rating due to the potential for escape sequence injection leading to unexpected terminal behavior.
2
How do I fix CVE-2024-28085?
To fix CVE-2024-28085, update to the latest version of util-linux that includes the patch for this vulnerability.
3
What versions of util-linux are affected by CVE-2024-28085?
CVE-2024-28085 affects all versions of util-linux wall prior to the patched release.
4
What kinds of systems are impacted by CVE-2024-28085?
CVE-2024-28085 potentially impacts any Unix-like systems using the util-linux package with the wall utility.
5
Is CVE-2024-28085 a remote or local vulnerability?
CVE-2024-28085 is considered a local vulnerability as it requires local access to exploit the escape sequence injection.