CVE-2017-16544
Description
In the add_match function in libbb/lineedit.c in BusyBox through 1.27.2, the tab autocomplete feature of the shell, used to get a list of filenames in a directory, does not sanitize filenames and results in executing any escape sequence in the terminal. This could potentially result in code execution, arbitrary file writes, or other attacks.
Risk Information
Base Score
8.8
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
3.313
Associated Vulnerability
| Vulnerability | OS Platform |
|---|---|
| Tiny utilities for small and embedded systems (USN-3935-1) udhcpc_1.27.2-2ubuntu3.2_i386.deb | Linux |
| Tiny utilities for small and embedded systems (USN-3935-1) udhcpc_1.27.2-2ubuntu3.2_amd64.deb | Linux |
| Tiny utilities for small and embedded systems (USN-3935-1) udhcpd_1.27.2-2ubuntu3.2_i386.deb | Linux |
| Tiny utilities for small and embedded systems (USN-3935-1) udhcpd_1.27.2-2ubuntu3.2_amd64.deb | Linux |
| SUSE-SU-2022:4253-1(SUSE Linux Enterprise Server 12-SP5 ) busybox-1.35.0-4.3.1.x86_64.rpm | Linux |
| SUSE-SU-2022:3959-1(SUSE Linux Enterprise Module for Basesystem 15-SP4 ) busybox-static-1.35.0-150400.3.3.1.x86_64.rpm | Linux |
| Tiny utilities for small and embedded systems (USN-3935-1) udhcpc_1.27.2-2ubuntu3.2_i386.deb | Linux |
| Tiny utilities for small and embedded systems (USN-3935-1) udhcpc_1.27.2-2ubuntu3.2_amd64.deb | Linux |
| Tiny utilities for small and embedded systems (USN-3935-1) udhcpd_1.27.2-2ubuntu3.2_i386.deb | Linux |
| Tiny utilities for small and embedded systems (USN-3935-1) udhcpd_1.27.2-2ubuntu3.2_amd64.deb | Linux |
Patch Details
No records foundReferences
https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234