-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEUMSg3c8x5FLOsZtRZWnYVadEvpMFAmYET/4ACgkQZWnYVadE
vpOCQg//YS1NgGGmKnUI9UriNKwqObC1SMgWnC1CEdqRbi8rqDgnGN1WsOa/Nnhe
dAwfQkOxTUfeez8ZjXGBDGDN4Z468GHbpmA87CyXhUfRm2YOK4B49VP+3OJpaIX3
hWgzN4yjHWhAfCsaFUHyimFWYdQsw8zIvGcXKJMuHLyDVK4otvRncsLwnoWqoj97
Xe73tws+ijwxVWye3gpj1wlfPQoah8++aRRYyQBDSysjATiAluzy33MSJ3WQ8qO9
Zm7XmbCuhnBfLYf6CpLYfxQERuL1BNXe86yLik0bJCxlXdb+EVKcrMZtc47/D82X
2RrgjHs5ukS4hl9ENt2IR64Jehl9BOJ90TE0riqlwWPn0tohYTWKF5qI45qkttiN
iAFo9fA1O7Hy4KjWsqTLgFc618a/JyWBPvbKoajKCx9NhMb5ePQwPIa92nDZAH70
KGLeaZngnIinq+t95mZaBIatssjUN7qfXpHZe8OL+w5z4voxt2oTk9Zdjk71PWMP
kmTHzjEFJy7EaZhF6XNt92jtHaBaokpbcnch8N3MqrWNBThwVEcwL4NS7FizDkwU
Q/E4UlMru5pjGfVRwCHj28gCh/Q7b88btl/gH8qG63y5nrnCr3klChW4o4vOxts3
17F4jHUIy+YpttF0N8RXS08j1VoBCz7+hw78DNu2yKLmga8iU2w=
=+hk4
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-6719-1
March 27, 2024
util-linux vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 23.10
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
Summary:
util-linux could be made to expose sensitive information.
Software Description:
- util-linux: miscellaneous system utilities
Details:
Skyler Ferrante discovered that the util-linux wall command did not filter
escape sequences from command line arguments. A local attacker could
possibly use this issue to obtain sensitive information.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 23.10:
util-linux 2.39.1-4ubuntu2.1
Ubuntu 22.04 LTS:
util-linux 2.37.2-4ubuntu3.3
Ubuntu 20.04 LTS:
util-linux 2.34-0.1ubuntu9.5
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-6719-1
CVE-2024-28085
Package Information:
https://launchpad.net/ubuntu/+source/util-linux/2.39.1-4ubuntu2.1
https://launchpad.net/ubuntu/+source/util-linux/2.37.2-4ubuntu3.3
https://launchpad.net/ubuntu/+source/util-linux/2.34-0.1ubuntu9.5
No comments:
Post a Comment