CVE-2022-28391 BusyBox through 1.35.0 allows remote attackers to execute arbitrary code if netstat is used to print a DNS PTR record's value to a VT compatible terminal. Alternatively, the attacker could choose to change the terminal's colors.
Nobody has claimed this yet.
Assessment
- Difficulty
- 5/5
- Estimated time
- Over a week
- Newbie friendliness
- 20/100
- Issue type
- Bug
- Clarity
- Needs clarification
- Activity status
- Stale
- Tech stack
- docker
- Domain
- operating-systems, security
Research direction
Start with the linked NVD entry and the BusyBox image/version context. The issue names no files, tests, or entry points, so determine the affected image scope and appropriate remediation before changing anything. Done means the vulnerability is addressed and the resulting image is verified against CVE-2022-28391.
Written by the indexing model from the issue text.
Description
CVE-2022-28391
BusyBox through 1.35.0 allows remote attackers to execute arbitrary code if netstat is used to print a DNS PTR record's value to a VT compatible terminal. Alternatively, the attacker could choose to change the terminal's colors.
Severity: Critical with 9.8 score
- Dominant language
- Dockerfile
- Stars
- 446
- Forks
- 140
- Avg merge
- 1h 26m
- Merged PRs (30d)
- 1
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from docker-library/busybox
-
Difficulty 5/5 Over a week Newbie friendliness 25/100
docker-library/busybox#176 · 2 comments ·
-
Difficulty 4/5 3-5 days Newbie friendliness 25/100
docker-library/busybox#148 · 3 comments ·
-
Difficulty 3/5 1-2 days Newbie friendliness 45/100
docker-library/busybox#143 · 4 comments ·
-
Request
Difficulty 5/5 Over a week Newbie friendliness 25/100
docker-library/busybox#80 · 11 comments · 6 reactions ·
All issues in docker-library/busybox
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
-
needs: triage type: bug
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
-
bug spec-mismatch
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
-
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
-
[Bug]: isStartupEntryInstalled treats access-denied as not-installed, duplicates Windows login items Openclawsweeper:bulk-filed clawsweeper:no-new-fix-pr clawsweeper:source-repro impact:other issue-rating: 🦞 diamond lobster P2
Difficulty 2/5 1-3 hours Newbie friendliness 78/100