CVE-2024-28085 is a low-severity vulnerability in the 'wall' utility (util-linux through 2.40), affecting Debian and kernel Linux distributions. It allows escape sequences to be sent to other users' terminals via argv, potentially leading to account takeover through crafted prompts. The CVSS score is 3.3 (LOW), indicating local access with low attack complexity and no confidentiality or availability impact, but a low integrity impact. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered significant community discussion and media coverage, suggesting awareness and potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.24, < 2.39.4CPE matchmatch criteria | cpe:2.3:a:kernel:util-linux:*:*:*:*:*:*:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2024-28085
Oct 8, 2024HP ThinPro 8.0 SP 9 Security Updates
Jun 17, 2024HP ThinPro 8.0 SP 9 Security Updates
Jun 17, 2024util-linux: CVE-2024-28085: wall: escape sequence injection
Mar 27, 2024wall in util-linux through 2.40 often installed with setgid tty permissions allows escape sequences to be sent to other users' terminals through argv. (Specifically escape sequences received from stdin are blocked but escape sequences received from argv are not blocked.) There may be plausible scenarios where this leads to account takeover.
Mar 12, 2024