Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Mageia 8 MGASA-2022-0135 Moderate: BusyBox Remote Code Execution

mageia
Calendar Grey April 9, 2022
Dist Mageia Esm H88
Latest BusyBox revisions address a security flaw which may allow remote code execution through improper use of netstat, released on 09 April 2022.
BusyBox through 1.35.0 allows remote attackers to execute arbitrary code if netstat is used to print a DNS PTR record's value to a VT compatible terminal

Summary

BusyBox through 1.35.0 allows remote attackers to execute arbitrary code if netstat is used to print a DNS PTR record's value to a VT compatible terminal. Alternatively, the attacker could choose to change the terminal's colors. (CVE-2022-28391)

References

- https://bugs.mageia.org/show_bug.cgi?id=30246

- https://nvd.nist.gov/vuln/detail/CVE-2022-28391

-

- https://www.cve.org/CVERecord?id=CVE-2022-28391

Resolution

SRPMS

- 8/core/busybox-1.34.1-1.1.mga8

Severity
important
Lowest
Low
Medium
High
Critical

Publication date: 09 Apr 2022
URL: https://advisories.mageia.org/MGASA-2022-0135.html
Type: security
CVE: CVE-2022-28391

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here