ZeroHour

CVE-2017-16544

PoC ×13
CVSS 3.1
8.8 high
EPSS
6%p93
Published
()
Modified
Description

In the add_match function in libbb/lineedit.c in BusyBox through 1.27.2, the tab autocomplete feature of the shell, used to get a list of filenames in a directory, does not sanitize filenames and results in executing any escape sequence in the terminal. This could potentially result in code execution, arbitrary file writes, or other attacks.

Vendors
busyboxdebianvmwareredlioncanonical
Products
busybox, debian linux, esxi, n-tron 702-w firmware, n-tron 702m12-w firmware, ubuntu linux
Weakness
CWE-94
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news