https://seclists.org/oss-sec/2024/q1/264: CVE-2024-28085: Escape sequence injection in util-linux wall
Published Mar 28, 2024
·Updated
Affected Software
1 affected component
util-linux wall
Frequently Asked Questions
1
What is the severity of CVE-2024-28085?
CVE-2024-28085 has been classified with a high severity due to the potential for escape sequence injection.
2
How do I fix CVE-2024-28085?
To fix CVE-2024-28085, update util-linux wall to the latest version that addresses this vulnerability.
3
What kind of systems are affected by CVE-2024-28085?
CVE-2024-28085 affects systems using the util-linux wall component for sending messages to users.
4
What are the potential impacts of CVE-2024-28085?
The potential impacts of CVE-2024-28085 include the execution of arbitrary escape sequences and possible unauthorized command execution.
5
Is there a workaround for CVE-2024-28085 while waiting for a patch?
A possible workaround for CVE-2024-28085 is to restrict access to the wall command to trusted users only.