wall in util-linux through 2.40, often installed with setgid tty permissions, allows escape sequences to be sent to other users' terminals through argv. (Specifically, escape sequences received from stdin are blocked, but escape sequences received from argv are not blocked.) There may be plausible scenarios where this leads to account takeover.
Metrics
Affected Vendors & Products
References
History
Mon, 26 Aug 2024 22:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-150 | |
Metrics |
cvssV3_1
|
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2024-03-27T00:00:00
Updated: 2024-08-26T20:25:27.912Z
Reserved: 2024-03-03T00:00:00
Link: CVE-2024-28085
Vulnrichment
Updated: 2024-08-02T00:48:48.228Z
NVD
Status : Awaiting Analysis
Published: 2024-03-27T19:15:48.367
Modified: 2024-08-26T21:35:09.310
Link: CVE-2024-28085
Redhat