Argument injection vulnerability in login (login-utils/login.c) in util-linux-ng 2.14 and earlier makes it easier for remote attackers to hide activities by modifying portions of log events, as demonstrated by appending an "addr=" statement to the login name, aka "audit log injection."
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2008-04-23 22:05
Updated : 2023-02-12 18:19
NVD link : CVE-2008-1926
Mitre link : CVE-2008-1926
JSON object : View
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')
Products Affected
linux
- util-linux