In netstat in BusyBox through 1.37.0, local users can launch of network application with an argv[0] containing an ANSI terminal escape sequence, leading to a denial of service (terminal locked up) when netstat is used by a victim.
References
Configurations
No configuration.
History
23 Apr 2025, 23:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
23 Apr 2025, 18:16
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-04-23 18:16
Updated : 2025-04-23 23:15
NVD link : CVE-2024-58251
Mitre link : CVE-2024-58251
CVE.ORG link : CVE-2024-58251
JSON object : View
Products Affected
No product.
CWE
CWE-150
Improper Neutralization of Escape, Meta, or Control Sequences