|
|
Log in / Subscribe / Register

Mageia alert MGASA-2024-0112 (util-linux)

From:  Mageia Updates <buildsystem-daemon@mageia.org>
To:  updates-announce@ml.mageia.org
Subject:  [updates-announce] MGASA-2024-0112: Updated util-linux packages fix security vulnerability
Date:  Sat, 06 Apr 2024 21:54:17 +0200
Message-ID:  <20240406195417.C4418A00FE@duvel.mageia.org>
Archive-link:  Article

MGASA-2024-0112 - Updated util-linux packages fix security vulnerability Publication date: 06 Apr 2024 URL: https://advisories.mageia.org/MGASA-2024-0112.html Type: security Affected Mageia releases: 9 CVE: CVE-2024-28085 Description: wall in util-linux through 2.40, often installed with setgid tty permissions, allows escape sequences to be sent to other users' terminals through argv. (Specifically, escape sequences received from stdin are blocked, but escape sequences received from argv are not blocked.) There may be plausible scenarios where this leads to account takeover. (CVE-2024-28085) References: - https://bugs.mageia.org/show_bug.cgi?id=33025 - https://www.openwall.com/lists/oss-security/2024/03/27/5 - https://ubuntu.com/security/notices/USN-6719-1 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-2... SRPMS: - 9/core/util-linux-2.38.1-1.1.mga9


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds