CVE-2022-28391

BusyBox through 1.35.0 allows remote attackers to execute arbitrary code if netstat is used to print a DNS PTR record's value to a VT compatible terminal. Alternatively, the attacker could choose to change the terminal's colors.
Argument Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.8 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 87%
Affected Products (NVD)
VendorProductVersion
busyboxbusybox
𝑥
≤ 1.35.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
busybox
bookworm
1:1.35.0-4
fixed
bullseye
1:1.30.1-6
fixed
sid
1:1.37.0-4
fixed
trixie
1:1.37.0-4
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
busybox
bionic
deferred
focal
deferred
impish
ignored
jammy
deferred
kinetic
ignored
lunar
ignored
mantic
ignored
noble
deferred
trusty
deferred
xenial
deferred
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
busybox
Amazon Linux 1
1:1.34.1-1.14.amzn1
fixed
busybox-debuginfo
Amazon Linux 1
1:1.34.1-1.14.amzn1
fixed
busybox-petitboot
Amazon Linux 1
1:1.34.1-1.14.amzn1
fixed
Azure Linux logo
Azure Linux Releases
Azure Package
Release
busybox
Azure Linux 3.0
0:1.36.1-3.azl3
fixed
CBL-Mariner 1.0
0:1.34.1-2.cm1
fixed
CBL-Mariner 2.0
0:1.35.0-2.cm2
fixed