CVE-2024-28085

SOURCE - nist

Summary

wall in util-linux through 2.40, often installed with setgid tty permissions, allows escape sequences to be sent to other users' terminals through argv. (Specifically, escape sequences received from stdin are blocked, but escape sequences received from argv are not blocked.) There may be plausible scenarios where this leads to account takeover.

EPSS Score: 0.00046 (0.165)

Common Weakness Enumeration (CWE)

SOURCE - nist
SOURCE - redhat

Privilege Chaining


debian

CREATED


UPDATED



EXPLOITABILITY SCORE

-


EXPLOITS FOUND
-

COMMON WEAKNESS ENUMERATION (CWE)-
RATING UNAVAILABLE FROM SOURCE
PackageTypeOS NameOS VersionAffected RangesFix Versions
debian/util-linuxdebdebian12<2.38.1-5+deb12u12.38.1-5+deb12u1
debian/util-linuxdebdebian11<2.36.1-8+deb11u22.36.1-8+deb11u2
debian/util-linuxdebdebianunstable<2.39.3-112.39.3-11
debian/util-linuxdebdebian10<2.33.1-0.1+deb10u12.33.1-0.1+deb10u1
debian/util-linuxdebdebian13<2.39.3-112.39.3-11

Severity and metrics

No CVSS data available from this source.

nist

CREATED


UPDATED



EXPLOITABILITY SCORE

-


EXPLOITS FOUND
-

COMMON WEAKNESS ENUMERATION (CWE)
RATING UNAVAILABLE FROM SOURCE

alpine

CREATED


UPDATED



EXPLOITABILITY SCORE

-


EXPLOITS FOUND
-

COMMON WEAKNESS ENUMERATION (CWE)-
RATING UNAVAILABLE FROM SOURCE

ubuntu

CREATED


UPDATED



EXPLOITABILITY SCORE

-


EXPLOITS FOUND
-

COMMON WEAKNESS ENUMERATION (CWE)-

CVSS SCORE

N/Amedium

redhat

CREATED


UPDATED



EXPLOITABILITY SCORE

2.0


EXPLOITS FOUND
-

COMMON WEAKNESS ENUMERATION (CWE)

CVSS SCORE

8.4high

inthewild

CREATED


UPDATED



EXPLOITABILITY SCORE

-


EXPLOITS FOUND

-


COMMON WEAKNESS ENUMERATION (CWE)-
RATING UNAVAILABLE FROM SOURCE