Home
LOW: 2.5 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:LDefault status
unknown
Any version
affected
Description
In netstat in BusyBox through 1.37.0, local users can launch of network application with an argv[0] containing an ANSI terminal escape sequence, leading to a denial of service (terminal locked up) when netstat is used by a victim.
Problem types
CWE-150 Improper Neutralization of Escape, Meta, or Control Sequences
Product status
Any version
References
www.openwall.com/lists/oss-security/2025/04/23/6
bugs.busybox.net/show_bug.cgi?id=15922