Advisories ยป MGASA-2024-0112

Updated util-linux packages fix security vulnerability

Publication date: 06 Apr 2024
Modification date: 06 Apr 2024
Type: security
Affected Mageia releases : 9
CVE: CVE-2024-28085

Description

wall in util-linux through 2.40, often installed with setgid tty
permissions, allows escape sequences to be sent to other users'
terminals through argv. (Specifically, escape sequences received from
stdin are blocked, but escape sequences received from argv are not
blocked.) There may be plausible scenarios where this leads to account
takeover. (CVE-2024-28085)
                

References

SRPMS

9/core