SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2024-28085

wall in util-linux through 2.40, often installed with setgid tty permissions, allows escape sequences to be sent to other users' terminals through argv.

LOW 3.3EPSS 2.24%

Does this matter?

Lower severity and a low EPSS score (2.24%). Track it; it rarely justifies an emergency change on its own.

Description

wall in util-linux through 2.40, often installed with setgid tty permissions, allows escape sequences to be sent to other users' terminals through argv. (Specifically, escape sequences received from stdin are blocked, but escape sequences received from argv are not blocked.) There may be plausible scenarios where this leads to account takeover.

CVSS 3.1
3.3 LOWCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
EPSS
2.24% probability · 82th percentile
CISA KEV
Not listed
Weakness
CWE-150
Affected
kernel/util-linux · debian/debian linux
Source
cve@mitre.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.