CVE-2024-28085 Skyler Ferrante discovered that the wall(1) utility found in util-linux, a collection of system utilities for Linux, does not . ------------------------------------------------------------------------- Debian LTS Advisory DLA-3782-1
gpg needs to be setuid to make use of protected memory space, however thesetgid bit allowed gpg user to overwrite goup root writable files and istherefore unnecessary.. - - --------------------------------------------------------------------- GENTOO LINUX SECURITY ANNOUNCEMENT 200307-06 - - --------------------------------------------------------------------- PACKAGE : gnupg SUMMARY : gpg setgid DATE : 2003-07-19 14:27 UTC EXPLOIT : local VERSIONS AFFECTED : =gnupg-1.2.2-r1 CVE : - - --------------------------------------------------------------------- gpg needs to be setuid to make use of protected memory space, however the setgid bit allowed gpg user to overwrite goup root writable files and is therefor unnecessary. SOLUTION It is recommended that all Gentoo Linux users who are running app-crypt/gnupg upgrade to gnupg-1.2.2-r1 as follows emerge sync emerge gnupg emerge clean - - ---------------------------------------------------------------------
Get the latest Linux and open source security news straight to your inbox.