PT-2022-3700 · Busybox+2 · Busybox+2

Ariadne Conill

·

Published

2022-04-03

·

Updated

2024-05-28

·

CVE-2022-28391

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions BusyBox versions prior to 1.35.0
Description The issue is related to the lack of input sanitization in the BusyBox command-line utility set, specifically affecting the netstat utility when printing DNS PTR records to a VT-compatible terminal. This could allow a remote attacker to execute arbitrary code or change the terminal's colors.
Recommendations For versions prior to 1.35.0, update to version 1.35.0 or later to resolve the issue. As a temporary workaround, consider restricting the use of the netstat utility with DNS PTR records on VT-compatible terminals until a patch is available.

Exploit

Fix

RCE

Argument Injection

OS Command Injection

Command Injection

Weakness Enumeration

Related Identifiers

AZL-41790
AZL-9311
BDU:2022-04487
BDU:2022-04661
CVE-2022-28391
MGASA-2022-0135
OESA-2022-1624
ROSA-SA-2024-2426

Affected Products

Astra Linux
Busybox
Red Os