QID 354635

Date Published: 2023-01-02

QID 354635: Amazon Linux Security Advisory for busybox : AL2012-2022-367

Package updates are available for Amazon Linux that fix the following vulnerabilities:
CVE-2022-28391:
2080958: CVE-2022-28391 busybox: remote attackers may execute arbitrary code if netstat is used An escape sequence injection attack was found in BusyBox on Alpine. For this issue to occur, a remote host's virtual terminal must contain an escape sequence, and the victim must then execute netstat. This flaw allows an attacker can inject arbitrary code, leading to a loss of integrity.

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as High - 6.8 severity.
  • Solution
    Administrators are advised to apply the appropriate software updates.
    Vendor References

    CVEs related to QID 354635

    Software Advisories
    Advisory ID Software Component Link
    AL2012-2022-367 Amazon Linux Bare Metal URL Logo docs.aws.amazon.com/AWSEC2/latest/UserGuide/install-updates.html