Remote Code Execution in BusyBox by Alpine Linux
CVE-2022-28391

8.8HIGH

Key Information:

Vendor

Busybox

Status
Vendor
CVE Published:
3 April 2022

What is CVE-2022-28391?

A vulnerability in BusyBox through version 1.35.0 allows remote attackers to leverage the 'netstat' utility to execute arbitrary code by printing a DNS PTR record's value to a VT compatible terminal. Furthermore, this flaw can enable an attacker to manipulate terminal colors, posing a significant security risk. It is essential for users of affected versions to upgrade and apply patches to mitigate potential exploits.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.