VDB

BDU%3A2025-08694

BDU%3A2025-08694 PUBLISHED CVSS 6.099999904632568 MEDIUM

Reported by mitre · Published November 20, 2017

In the add_match function in libbb/lineedit.c in BusyBox through 1.27.2, the tab autocomplete feature of the shell, used to get a list of filenames in a directory, does not sanitize filenames and results in executing any escape sequence in the terminal. This could potentially result in code execution, arbitrary file writes, or other attacks.

Risk Scores

CVSS 2.0
6.099999904632568

Affected Products

VendorProductVersions
n/an/an/a
n/an/an/a
Novell Inc., Red Hat Inc., Сообщество свободного программного обеспечения, ООО «Ред Софт», Canonical Ltd., АО «НТЦ ИТ РОСА», АО «ИВК», ООО «РусБИТех-Астра», Free Software Foundation, Inc., АО «СберТех», АО "НППКТ"Suse Linux Enterprise Desktop, OpenSUSE Leap, SUSE Linux Enterprise Server for SAP Applications, Suse Linux Enterprise Server, OpenShift Container Platform, Debian GNU/Linux, РЕД ОС (запись в едином реестре российских программ №3751), Ubuntu, Red Hat Enterprise Linux, openSUSE Leap Micro, ROSA Virtualization (запись в едином реестре российских программ №5091), АЛЬТ СП 10, Astra Linux Special Edition (запись в едином реестре российских программ №369), ROSA Virtualization 3.0 (запись в едином реестре российских программ №21308), GnuTLS, Platform V SberLinux OS Server (запись в едином реестре российских программ №18785), ОСОН ОСнова Оnyx (запись в едином реестре российских программ №5913)

Timeline

  • Nov 20, 2017 CVE Published
  • Jun 9, 2025 CVE Updated
  • Apr 18, 2026 PoC Published

References

…and 13 more

Open in Interactive Console →
$ Console Community · 100/wk Open console ›