Alerts This Week
Warning Icon 1 914
Alerts This Week
Warning Icon 1 914

Debian: DSA-5650-1 Critical: Util-Linux Escape Sequences Exploit

debian
Calendar Grey March 31, 2024
Debian Logo
Debian Security Notice DSA-5651-1 highlights a flaw in the util-linux handling of escape sequences; it is recommended to apply updates to avert potential data exposure.
Skyler Ferrante discovered that the wall tool from util-linux does not properly handle escape sequences from command line arguments

Summary

With this update wall and write are not anymore installed with setgid
tty.

For the oldstable distribution (bullseye), this problem has been fixed
in version 2.36.1-8+deb11u2.

For the stable distribution (bookworm), this problem has been fixed in
version 2.38.1-5+deb12u1.

We recommend that you upgrade your util-linux packages.

For the detailed security status of util-linux please refer to its
security tracker page at:
https://security-tracker.debian.org/tracker/source-package/util-linux

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/



Severity
critical
Lowest
Low
Medium
High
Critical

Package: util-linux
CVE ID: CVE-2024-28085

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here