Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:25293
HistoryMay 10, 2020 - 11:24 p.m.

Arbitrary Code Execution

2020-05-1023:24:36
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
17

0.005 Low

EPSS

Percentile

77.0%

busybox is vulnerable to arbitrary code execution. The vulnerability exists in the add_match function in libbb/lineedit.c in BusyBox through 1.27.2, the tab autocomplete feature of the shell, used to get a list of filenames in a directory, does not sanitize filenames and results in executing any escape sequence in the terminal. This could potentially result in code execution, arbitrary file writes, or other attacks.

References