PT-2017-4120 · Busybox+2 · Busybox+2

Publicado

2017-11-05

·

Atualizado

2024-06-15

·

CVE-2017-16544

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions BusyBox versions 1.27.2 and earlier
Description The tab autocomplete feature of the shell in BusyBox does not sanitize filenames. This results in executing any escape sequence in the terminal, potentially leading to code execution, arbitrary file writes, or other attacks. The issue is related to the add match function in libbb/lineedit.c.
Recommendations For BusyBox versions 1.27.2 and earlier, consider disabling the tab autocomplete feature until a patch is available. Restrict access to sensitive directories to minimize the risk of exploitation. Avoid using the tab autocomplete feature in untrusted environments. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Code Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2021-03363
CVE-2017-16544
DLA-1445-1
DLA-2559-1
OPENSUSE-SU-2022:0135-1
OPENSUSE-SU-2022_0135-1
OPENSUSE-SU-2022_3959-1
OPENSUSE-SU-2024:11738-1
SUSE-SU-2022:0135-1
SUSE-SU-2022:0135-2
SUSE-SU-2022:3959-1
SUSE-SU-2022:4253-1
USN-3935-1

Produtos afetados

Busybox
Suse
Ubuntu