Argument injection vulnerability in login (login-utils/login.c) in util-linux-ng 2.14 and earlier makes it easier for remote attackers to hide activities by modifying portions of log events, as demonstrated by appending an "addr=" statement to the login name, aka "audit log injection."
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2008-04-24 05:05
Updated : 2024-02-04 17:33
NVD link : CVE-2008-1926
Mitre link : CVE-2008-1926
CVE.ORG link : CVE-2008-1926
JSON object : View
Products Affected
linux
- util-linux
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')