New Linux Bug Could Lead to User Password Leaks and Clipboard Hijacking
ID: 9be2596c-ff14-5f27-a9e1-24c3986e96ca
STIX ID: report--9be2596c-ff14-5f27-a9e1-24c3986e96ca
Feed Name: The Hacker News
The report discloses CVE-2024-28085 (“WallEscape”), a vulnerability in the util-linux wall command that fails to neutralize escape sequences, enabling unprivileged users to place arbitrary text on other users' terminals (e.g., display fake sudo prompts to capture passwords) when mesg is enabled and wall is setgid—conditions present by default on Ubuntu 22.04 and Debian Bookworm; updating to util-linux 2.40 mitigates the issue. The article also notes a separate kernel netfilter use-after-free (CVE-2024-1086) that could allow local denial-of-service or code execution and has been addressed upstream.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
