VDB

MAGEIA-2024-112

MAGEIA-2024-112 PUBLISHED

wall in util-linux through 2.40, often installed with setgid tty permissions, allows escape sequences to be sent to other users' terminals through argv. (Specifically, escape sequences received from stdin are blocked, but escape sequences received from argv are not blocked.) There may be plausible scenarios where this leads to account takeover. (CVE-2024-28085)

Affected Products

VendorProductVersions
Mageiakdevelop-php0, 23.04.3-1.mga9
Mageiabomber0, 23.04.3-1.mga9
Mageiadragon0, 23.04.3-1.mga9
Mageiakgeography23.04.3-1.mga9, 0
Mageiakpmcore23.04.3-1.mga9, 0
Mageiakapptemplate23.04.3-1.mga9, 0
Mageiakalgebra23.04.3-1.mga9, 0
Mageiamailimporter0, 23.04.3-1.mga9
Mageiaitinerary23.04.3-1.mga9, 0
Mageialibkleo0, 23.04.3-1.mga9
Mageiakrecorder23.04.3-1.mga9, 0
Mageiatokodon23.04.3-1.mga9, 0
Mageiapartitionmanager23.04.3-1.mga9, 0
Mageiakde-dev-scripts0, 23.04.3-1.mga9
Mageiakrfb0, 23.04.3-1.mga9
Mageiakipi-plugins0, 23.04.3-1.mga9
Mageiakmix0, 23.04.3-1.mga9
Mageiakgoldrunner0, 23.04.3-1.mga9
Mageiaspectacle23.04.3-1.mga9, 0
Mageiaksquares23.04.3-1.mga9, 0

…and 233 more

Timeline

  • Mar 22, 2024 CVE Published
  • Apr 6, 2024 CVE Updated
  • Mar 17, 2026 Distribution Patch
  • Mar 17, 2026 Security Advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›