USN-6719-2: util-linux vulnerability
USN-6719-1 fixed a vulnerability in util-linux. Unfortunately, it was discovered that the fix did not fully address the issue. This update removes the setgid permission bit from the wall and write utilities. Original advisory details: Skyler Ferrante discovered that the util-linux wall command did not filter escape sequences from command line arguments. A local attacker could possibly use this issue to obtain sensitive information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-6719-2?
USN-6719-2 addresses a critical vulnerability in the util-linux package that could allow unauthorized access or execution of commands.
How do I fix USN-6719-2?
To resolve USN-6719-2, update the util-linux package to version 2.39.1-4ubuntu2.2 or higher for Ubuntu 23.10, 2.37.2-4ubuntu3.4 or higher for Ubuntu 22.04, or 2.34-0.1ubuntu9.6 or higher for Ubuntu 20.04.
What specific utilities are affected by USN-6719-2?
The urban-linux update in USN-6719-2 specifically affects the wall and write utilities.
Is USN-6719-2 a follow-up to another advisory?
Yes, USN-6719-2 is a follow-up to USN-6719-1, which initially addressed the vulnerability but did not fully resolve it.
What could happen if I don't address USN-6719-2?
Failing to address USN-6719-2 may leave your system vulnerable to unauthorized command execution and potential security breaches.