HIGH · 8.8

CVE-2017-16544

In the add_match function in libbb/lineedit.c in BusyBox through 1.27.2, the tab autocomplete feature of the shell, used to get a list of filenames in a directory, does not sanitize filenames and resu...

Vulnerability Description

In the add_match function in libbb/lineedit.c in BusyBox through 1.27.2, the tab autocomplete feature of the shell, used to get a list of filenames in a directory, does not sanitize filenames and results in executing any escape sequence in the terminal. This could potentially result in code execution, arbitrary file writes, or other attacks.

CVSS Score

8.8

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
BusyboxBusybox<= 1.27.2
DebianDebian Linux8.0
VmwareEsxi6.0
RedlionN-Tron 702-W FirmwareAll versions
RedlionN-Tron 702-W-
RedlionN-Tron 702M12-W FirmwareAll versions
RedlionN-Tron 702M12-W-
CanonicalUbuntu Linux14.04

Related Weaknesses (CWE)

References

FAQ

What is CVE-2017-16544?

CVE-2017-16544 is a vulnerability with a CVSS score of 8.8 (HIGH). In the add_match function in libbb/lineedit.c in BusyBox through 1.27.2, the tab autocomplete feature of the shell, used to get a list of filenames in a directory, does not sanitize filenames and resu...

How severe is CVE-2017-16544?

CVE-2017-16544 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2017-16544?

Check the references section above for vendor advisories and patch information. Affected products include: Busybox Busybox, Debian Debian Linux, Vmware Esxi, Redlion N-Tron 702-W Firmware, Redlion N-Tron 702-W.