CVE-2008-1926
Publication date 24 April 2008
Last updated 24 July 2024
Ubuntu priority
Argument injection vulnerability in login (login-utils/login.c) in util-linux-ng 2.14 and earlier makes it easier for remote attackers to hide activities by modifying portions of log events, as demonstrated by appending an "addr=" statement to the login name, aka "audit log injection."
Status
Package | Ubuntu Release | Status |
---|---|---|
util-linux | ||
Notes
mdeslaur
this is the CVE-2007-3102 issue from openssh marking not-affected as we don't use login from the util-linux package. It's not compiled.
Patch details
Package | Patch details |
---|---|
util-linux |