Home

Description

In tar in BusyBox through 1.37.0, a TAR archive can have filenames hidden from a listing through the use of terminal escape sequences.

PUBLISHED Reserved 2025-04-23 | Published 2025-04-23 | Updated 2026-06-02 | Assigner mitre




LOW: 3.2CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N

Problem types

CWE-451 User Interface (UI) Misrepresentation of Critical Information

Product status

Default status
unknown

Any version
affected

References

www.openwall.com/lists/oss-security/2025/04/23/5

www.openwall.com/lists/oss-security/2025/04/24/3

cert-portal.siemens.com/productcert/html/ssa-253495.html

bugs.busybox.net/show_bug.cgi?id=16018

www.busybox.net/downloads/

www.busybox.net

cve.org (CVE-2025-46394)

nvd.nist.gov (CVE-2025-46394)

Download JSON