wall in util-linux through 2.40, often installed with setgid tty permissions, allows escape sequences to be sent to other users' terminals through argv. (Specifically, escape sequences received from stdin are blocked, but escape sequences received from argv are not blocked.) There may be plausible scenarios where this leads to account takeover.
Metrics
Affected Vendors & Products
References
History
Tue, 04 Nov 2025 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Thu, 20 Mar 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Debian
Debian debian Linux Kernel Kernel util-linux |
|
| CPEs | cpe:2.3:a:kernel:util-linux:*:*:*:*:*:*:*:* cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* |
|
| Vendors & Products |
Debian
Debian debian Linux Kernel Kernel util-linux |
Sun, 16 Mar 2025 03:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
threat_severity
|
threat_severity
|
Mon, 26 Aug 2024 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-150 | |
| Metrics |
cvssV3_1
|
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published: 2024-03-27T00:00:00.000Z
Updated: 2025-11-04T18:30:25.092Z
Reserved: 2024-03-03T00:00:00.000Z
Link: CVE-2024-28085
Updated: 2024-08-02T00:48:48.228Z
Status : Modified
Published: 2024-03-27T19:15:48.367
Modified: 2025-11-04T19:17:04.917
Link: CVE-2024-28085