April 18, 2024
Cybersecurity student finds vulnerability in platform package
Skyler Ferrante, a fourth-year cybersecurity student, found a vulnerability in util-linux (CVE-2024-28085) that has allowed low-privilege users to send escape sequences to other users and enabled a user’s password to be leaked on some configurations. The discovery was mentioned on multiple news sites, including Hackaday and Bleeping Computer.