Executive brief
The 'wall' daemon, a utility used to broadcast messages to all logged-in users on a system, contains a vulnerability that can be exploited remotely. An attacker could use this flaw to disrupt system operations, trick users into revealing sensitive information, or potentially execute unauthorized commands. This poses a risk to the integrity of the system and the confidentiality of user data.
Technical details
The wall (write all) daemon contains a vulnerability that allows for remote exploitation. While the specific underlying weakness (such as a buffer overflow or improper input validation) is not detailed in the legacy advisory, the flaw permits an unauthenticated network attacker to perform several malicious actions. These include causing a denial of service, conducting social engineering by spoofing system messages, or achieving remote command execution. The CVSS 2.0 score of 6.8 reflects a partial impact on confidentiality, integrity, and availability.
Affected products
- unknown wall daemon
Timeline
- 1994-01-01: disclosed