PT-2017-4120 · Busybox+2 · Busybox+2

Published

2017-11-05

·

Updated

2024-06-15

·

CVE-2017-16544

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions BusyBox versions 1.27.2 and earlier
Description The tab autocomplete feature of the shell in BusyBox does not sanitize filenames. This results in executing any escape sequence in the terminal, potentially leading to code execution, arbitrary file writes, or other attacks. The issue is related to the add match function in libbb/lineedit.c.
Recommendations For BusyBox versions 1.27.2 and earlier, consider disabling the tab autocomplete feature until a patch is available. Restrict access to sensitive directories to minimize the risk of exploitation. Avoid using the tab autocomplete feature in untrusted environments. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-03363
CVE-2017-16544
DLA-1445-1
DLA-2559-1
OPENSUSE-SU-2022:0135-1
OPENSUSE-SU-2022_0135-1
OPENSUSE-SU-2022_3959-1
OPENSUSE-SU-2024:11738-1
SUSE-SU-2022:0135-1
SUSE-SU-2022:0135-2
SUSE-SU-2022:3959-1
SUSE-SU-2022:4253-1
USN-3935-1

Affected Products

Busybox
Suse
Ubuntu