CVE-2022-28391
Summary
| CVE | CVE-2022-28391 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-04-03 21:15:00 UTC |
| Updated | 2022-08-11 18:44:00 UTC |
| Description | BusyBox through 1.35.0 allows remote attackers to execute arbitrary code if netstat is used to print a DNS PTR record's value to a VT compatible terminal. Alternatively, the attacker could choose to change the terminal's colors. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| netstat is vulnerable to escape sequence injection (busybox) (#13661) · Issues · alpine / aports · GitLab | MISC | gitlab.alpinelinux.org | |
| git.alpinelinux.org/aports/plain/main/busybox/0001-libbb-sockaddr2str-ensure-only... | MISC | git.alpinelinux.org | |
| git.alpinelinux.org/aports/plain/main/busybox/0002-nslookup-sanitize-all-printed-... | MISC | git.alpinelinux.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 353972 Amazon Linux Security Advisory for busybox : ALAS-2022-1608
- 354635 Amazon Linux Security Advisory for busybox : AL2012-2022-367
- 500083 Alpine Linux Security Update for busybox
- 500157 Alpine Linux Security Update for busybox
- 500356 Alpine Linux Security Update for busybox
- 501388 Alpine Linux Security Update for busybox
- 501736 Alpine Linux Security Update for busybox
- 501951 Alpine Linux Security Update for busybox
- 502208 Alpine Linux Security Update for busybox
- 503878 Alpine Linux Security Update for busybox
- 671914 EulerOS Security Update for busybox (EulerOS-SA-2022-1988)
- 671924 EulerOS Security Update for busybox (EulerOS-SA-2022-1958)
- 671992 EulerOS Security Update for busybox (EulerOS-SA-2022-2151)
- 671999 EulerOS Security Update for busybox (EulerOS-SA-2022-2126)
- 900786 Common Base Linux Mariner (CBL-Mariner) Security Update for busybox (9315)
- 901344 Common Base Linux Mariner (CBL-Mariner) Security Update for busybox (9315-1)
- 901960 Common Base Linux Mariner (CBL-Mariner) Security Update for busybox (9311)
- 902060 Common Base Linux Mariner (CBL-Mariner) Security Update for busybox (9311-1)