- Offizieller Beitrag
Package : util-linux
CVE ID : CVE-2024-28085
Debian Bug : 1067849
Skyler Ferrante discovered that the wall tool from util-linux does not properly handle escape sequences from command line arguments. A local attacker can take advantage of this flaw for information disclosure.
With this update wall and write are not anymore installed with setgid tty.
For the oldstable distribution (bullseye), this problem has been fixed in version 2.36.1-8+deb11u2.
For the stable distribution (bookworm), this problem has been fixed in version 2.38.1-5+deb12u1.
We recommend that you upgrade your util-linux packages.
For the detailed security status of util-linux please refer to its security tracker page at:
Information on source package util-linux
Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/