Home
LOW: 3.2 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:NDefault status
unknown
Any version
affected
Description
In tar in BusyBox through 1.37.0, a TAR archive can have filenames hidden from a listing through the use of terminal escape sequences.
Problem types
CWE-451 User Interface (UI) Misrepresentation of Critical Information
Product status
Any version
References
www.openwall.com/lists/oss-security/2025/04/23/5
www.openwall.com/lists/oss-security/2025/04/24/3
cert-portal.siemens.com/productcert/html/ssa-253495.html
bugs.busybox.net/show_bug.cgi?id=16018