Recently, a vulnerability was discovered in the WALL utility, found in the packet supplied in util-linux, which is designed to send messages to terminals. The vulnerability, identified as CVE-2024-28085, allows attackers to launch attacks on the terminals of other users by manipulating ESCAPE sequences. The issue arises because the WALL utility blocks the use of Escape sequences in the input stream, but fails to do so for command line arguments, enabling attackers to perform ESCAPE-sequence manipulation on the terminals of other users.
For instance, by executing ‘Wall $(Printf “