7.5
CVSSv2

CVE-2008-1926

Published: 24/04/2008 Updated: 13/02/2023
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Argument injection vulnerability in login (login-utils/login.c) in util-linux-ng 2.14 and previous versions makes it easier for remote malicious users to hide activities by modifying portions of log events, as demonstrated by appending an "addr=" statement to the login name, aka "audit log injection."

Vulnerable Product Search on Vulmon Subscribe to Product

linux util-linux 2.13.0.1

linux util-linux 2.13

linux util-linux 2.13.1

linux util-linux 2.13.1.1

linux util-linux 2.14

Vendor Advisories

Synopsis Low: util-linux security and bug fix update Type/Severity Security Advisory: Low Topic An updated util-linux package that fixes one security issue and severalbugs is now availableThis update has been rated as having low security impact by the RedHat Security Response Team Description ...
Debian Bug report logs - #478135 util-linux: CVE-2008-1926 argument injection passed to audit Package: util-linux; Maintainer for util-linux is LaMont Jones <lamont@debianorg>; Source for util-linux is src:util-linux (PTS, buildd, popcon) Reported by: Nico Golde <nion@debianorg> Date: Sun, 27 Apr 2008 13:12:02 UTC ...