Logo
vulnerabilityCVE-2022-28391
Name
CVE-2022-28391
Source
NVD ( link)Debian ( link)
Description
BusyBox through 1.35.0 allows remote attackers to execute arbitrary code if netstat is used to print a DNS PTR record's value to a VT compatible terminal. Alternatively, the attacker could choose to change the terminal's colors.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
busybox
Patched

Vulnerability Ratings#


8.8
CVSSv31
8.8
CVSSv31
6.8
CVSSv2
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
1.37.0
Patched
buildroot
master
1.38.0
Patched
openwrt
master
1.38.0-r2
Not Affected
openwrt
openwrt-25.12
1.37.0-r6
Not Affected
yocto
kirkstone
1.35.0
Patched
yocto
master
1.38.0
Patched

Resolved with patches#


busybox (buildroot:2025.02.x)

#
Title
Author
Resolve
1
libbb: sockaddr2str: ensure only printable characters are
Ariadne Conill <ariadne@dereferenced.org>
CVE-2022-28391
2
nslookup: sanitize all printed strings with printable_string
Ariadne Conill <ariadne@dereferenced.org>
CVE-2022-28391

busybox (buildroot:master)

#
Title
Author
Resolve
1
libbb: sockaddr2str: ensure only printable characters are
Ariadne Conill <ariadne@dereferenced.org>
CVE-2022-28391
2
nslookup: sanitize all printed strings with printable_string
Ariadne Conill <ariadne@dereferenced.org>
CVE-2022-28391

busybox (yocto:kirkstone)

#
Title
Author
Resolve
1
libbb: sockaddr2str: ensure only printable characters are
Ariadne Conill <ariadne@dereferenced.org>
CVE-2022-28391
2
nslookup: sanitize all printed strings with
Ariadne Conill <ariadne@dereferenced.org>
CVE-2022-28391

busybox (yocto:master)

#
Title
Author
Resolve
1
libbb: sockaddr2str: ensure only printable characters are
Ariadne Conill <ariadne@dereferenced.org>
CVE-2022-28391
2
nslookup: sanitize all printed strings with
Ariadne Conill <ariadne@dereferenced.org>
CVE-2022-28391

busybox (yocto:scarthgap)

#
Title
Author
Resolve
1
libbb: sockaddr2str: ensure only printable characters are
Ariadne Conill <ariadne@dereferenced.org>
CVE-2022-28391
2
nslookup: sanitize all printed strings with
Ariadne Conill <ariadne@dereferenced.org>
CVE-2022-28391