CVE-2022-28391

Name
CVE-2022-28391
Description
BusyBox through 1.35.0 allows remote attackers to execute arbitrary code if netstat is used to print a DNS PTR record's value to a VT compatible terminal. Alternatively, the attacker could choose to change the terminal's colors.
NVD Severity
high
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
MISC https://git.alpinelinux.org/aports/plain/main/busybox/0002-nslookup-sanitize-all-printed-strings-with-printable.patch
MISC https://gitlab.alpinelinux.org/alpine/aports/-/issues/13661
MISC https://git.alpinelinux.org/aports/plain/main/busybox/0001-libbb-sockaddr2str-ensure-only-printable-characters-.patch

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:busybox:busybox:*:*:*:*:*:*:*:* busybox >= None <= 1.35.0

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
busybox 3.12-main 1.31.1-r22 Natanael Copa <ncopa@alpinelinux.org> fixed
busybox 3.15-main 1.34.1-r7 Natanael Copa <ncopa@alpinelinux.org> fixed
busybox 3.14-main 1.33.1-r8 Natanael Copa <ncopa@alpinelinux.org> fixed
busybox 3.13-main 1.32.1-r9 Natanael Copa <ncopa@alpinelinux.org> fixed
busybox 3.16-main 1.35.0-r18 Sören Tempel <soeren+alpine@soeren-tempel.net> fixed
busybox 3.17-main 1.35.0-r31 Sören Tempel <soeren+alpine@soeren-tempel.net> fixed