Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2022-28391

Опубликовано: 03 апр. 2022
Источник: debian
EPSS Низкий

Описание

BusyBox through 1.35.0 allows remote attackers to execute arbitrary code if netstat is used to print a DNS PTR record's value to a VT compatible terminal. Alternatively, the attacker could choose to change the terminal's colors.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
busyboxnot-affectedpackage

Примечания

  • https://gitlab.alpinelinux.org/alpine/aports/-/issues/13661

  • https://bugs.busybox.net/show_bug.cgi?id=15922

  • https://bugs.busybox.net/show_bug.cgi?id=14811

  • https://bugzilla.suse.com/show_bug.cgi?id=1198092#c3

EPSS

Процентиль: 91%
0.0719
Низкий

Связанные уязвимости

CVSS3: 8.8
ubuntu
около 3 лет назад

BusyBox through 1.35.0 allows remote attackers to execute arbitrary code if netstat is used to print a DNS PTR record's value to a VT compatible terminal. Alternatively, the attacker could choose to change the terminal's colors.

CVSS3: 6.5
redhat
около 3 лет назад

BusyBox through 1.35.0 allows remote attackers to execute arbitrary code if netstat is used to print a DNS PTR record's value to a VT compatible terminal. Alternatively, the attacker could choose to change the terminal's colors.

CVSS3: 8.8
nvd
около 3 лет назад

BusyBox through 1.35.0 allows remote attackers to execute arbitrary code if netstat is used to print a DNS PTR record's value to a VT compatible terminal. Alternatively, the attacker could choose to change the terminal's colors.

CVSS3: 8.8
msrc
около 3 лет назад

Описание отсутствует

CVSS3: 9.8
github
около 3 лет назад

BusyBox through 1.35.0 allows remote attackers to execute arbitrary code if netstat is used to print a DNS PTR record's value to a VT compatible terminal. Alternatively, the attacker could choose to change the terminal's colors.

EPSS

Процентиль: 91%
0.0719
Низкий