• CVE-2024-28085

发布时间: 2024年4月3日

修改时间: 2024年4月12日

概要

wall in util-linux through 2.40, often installed with setgid tty permissions, allows escape sequences to be sent to other users' terminals through argv. (Specifically, escape sequences received from stdin are blocked, but escape sequences received from argv are not blocked.) There may be plausible scenarios where this leads to account takeover.

CVSS v3 指标

NVD openEuler
CVSS评分 0.0
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

安全公告

公告名 概要 发布时间
KylinSec-SA-2024-3163 util-linux security update 2024年4月3日

影响产品

产品 状态
KY3.4-4A util-linux Fixed
KY3.4-5A util-linux Fixed
KY3.5.1 util-linux Fixed
KY3.5.2 util-linux Fixed