PT-2017-4120 · Busybox+2 · Busybox+2
Published
2017-11-05
·
Updated
2024-06-15
·
CVE-2017-16544
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
BusyBox versions 1.27.2 and earlier
Description
The tab autocomplete feature of the shell in BusyBox does not sanitize filenames. This results in executing any escape sequence in the terminal, potentially leading to code execution, arbitrary file writes, or other attacks. The issue is related to the
add match function in libbb/lineedit.c.Recommendations
For BusyBox versions 1.27.2 and earlier, consider disabling the tab autocomplete feature until a patch is available. Restrict access to sensitive directories to minimize the risk of exploitation. Avoid using the tab autocomplete feature in untrusted environments. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Busybox
Suse
Ubuntu