CVE-2022-28391

Name
CVE-2022-28391
Description
BusyBox through 1.35.0 allows remote attackers to execute arbitrary code if netstat is used to print a DNS PTR record's value to a VT compatible terminal. Alternatively, the attacker could choose to change the terminal's colors.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
MISC https://git.alpinelinux.org/aports/plain/main/busybox/0002-nslookup-sanitize-all-printed-strings-with-printable.patch
MISC https://gitlab.alpinelinux.org/alpine/aports/-/issues/13661
MISC https://git.alpinelinux.org/aports/plain/main/busybox/0001-libbb-sockaddr2str-ensure-only-printable-characters-.patch

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:busybox:busybox:*:*:*:*:*:*:*:* busybox >= None <= 1.35.0

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
busybox edge-main 1.35.0-r30 Sören Tempel <soeren+alpine@soeren-tempel.net> fixed
busybox edge-main 1.35.0-r29 Sören Tempel <soeren+alpine@soeren-tempel.net> fixed
busybox edge-main 1.35.0-r28 Sören Tempel <soeren+alpine@soeren-tempel.net> fixed
busybox edge-main 1.35.0-r27 Sören Tempel <soeren+alpine@soeren-tempel.net> fixed
busybox edge-main 1.35.0-r25 Sören Tempel <soeren+alpine@soeren-tempel.net> fixed
busybox edge-main 1.35.0-r24 Sören Tempel <soeren+alpine@soeren-tempel.net> fixed
busybox edge-main 1.35.0-r23 Sören Tempel <soeren+alpine@soeren-tempel.net> fixed
busybox edge-main 1.35.0-r22 Sören Tempel <soeren+alpine@soeren-tempel.net> fixed
busybox edge-main 1.35.0-r21 Sören Tempel <soeren+alpine@soeren-tempel.net> fixed
busybox edge-main 1.35.0-r20 Sören Tempel <soeren+alpine@soeren-tempel.net> fixed
busybox edge-main 1.35.0-r19 Sören Tempel <soeren+alpine@soeren-tempel.net> fixed
busybox edge-main 1.35.0-r18 Sören Tempel <soeren+alpine@soeren-tempel.net> fixed
busybox edge-main 1.35.0-r17 Sören Tempel <soeren+alpine@soeren-tempel.net> fixed
busybox edge-main 1.35.0-r16 Sören Tempel <soeren+alpine@soeren-tempel.net> fixed
busybox edge-main 1.35.0-r15 Sören Tempel <soeren+alpine@soeren-tempel.net> fixed
busybox edge-main 1.35.0-r14 Sören Tempel <soeren+alpine@soeren-tempel.net> fixed
busybox edge-main 1.35.0-r13 Sören Tempel <soeren+alpine@soeren-tempel.net> fixed
busybox edge-main 1.35.0-r12 Sören Tempel <soeren+alpine@soeren-tempel.net> fixed
busybox edge-main 1.35.0-r10 Sören Tempel <soeren+alpine@soeren-tempel.net> fixed
busybox edge-main 1.35.0-r7 Natanael Copa <ncopa@alpinelinux.org> fixed
busybox edge-main 1.34.0_r0 None possibly vulnerable
busybox edge-main 1.34.0-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
busybox edge-main 1.33.0-r5 None possibly vulnerable
busybox edge-main 1.30.1-r2 None possibly vulnerable
busybox edge-main 1.29.3-r10 None possibly vulnerable
busybox edge-main 1.28.3-r2 None possibly vulnerable
busybox edge-main 1.27.2-r4 None possibly vulnerable
busybox 3.22-main 1.35.0-r17 None fixed
busybox 3.22-main 1.35.0-r7 None fixed
busybox 3.22-main 1.34.0-r0 None possibly vulnerable
busybox 3.22-main 1.33.0-r5 None possibly vulnerable
busybox 3.22-main 1.30.1-r2 None possibly vulnerable
busybox 3.22-main 1.29.3-r10 None possibly vulnerable
busybox 3.22-main 1.28.3-r2 None possibly vulnerable
busybox 3.22-main 1.27.2-r4 None possibly vulnerable
busybox 3.21-main 1.35.0-r17 None fixed
busybox 3.21-main 1.35.0-r7 None fixed
busybox 3.21-main 1.34.0-r0 None possibly vulnerable
busybox 3.21-main 1.33.0-r5 None possibly vulnerable
busybox 3.21-main 1.30.1-r2 None possibly vulnerable
busybox 3.21-main 1.29.3-r10 None possibly vulnerable
busybox 3.21-main 1.28.3-r2 None possibly vulnerable
busybox 3.21-main 1.27.2-r4 None possibly vulnerable
busybox 3.20-main 1.35.0-r17 None fixed
busybox 3.20-main 1.35.0-r7 None fixed
busybox 3.20-main 1.34.0-r0 None possibly vulnerable
busybox 3.20-main 1.33.0-r5 None possibly vulnerable
busybox 3.20-main 1.30.1-r2 None possibly vulnerable
busybox 3.20-main 1.29.3-r10 None possibly vulnerable
busybox 3.20-main 1.28.3-r2 None possibly vulnerable
busybox 3.20-main 1.27.2-r4 None possibly vulnerable
busybox 3.19-main 1.35.0-r17 None fixed
busybox 3.19-main 1.35.0-r7 None fixed
busybox 3.19-main 1.34.0-r0 None possibly vulnerable
busybox 3.19-main 1.33.0-r5 None possibly vulnerable
busybox 3.19-main 1.30.1-r2 None possibly vulnerable
busybox 3.19-main 1.29.3-r10 None possibly vulnerable
busybox 3.19-main 1.28.3-r2 None possibly vulnerable
busybox 3.19-main 1.27.2-r4 None possibly vulnerable
busybox 3.18-main 1.35.0-r7 None fixed
busybox 3.17-main 1.35.0-r31 Sören Tempel <soeren+alpine@soeren-tempel.net> fixed
busybox 3.17-main 1.35.0-r30 Sören Tempel <soeren+alpine@soeren-tempel.net> fixed
busybox 3.17-main 1.35.0-r29 Sören Tempel <soeren+alpine@soeren-tempel.net> fixed
busybox 3.17-main 1.35.0-r7 None fixed
busybox 3.12-main 1.31.1-r22 Natanael Copa <ncopa@alpinelinux.org> fixed