High severity8.8NVD Advisory· Published Apr 3, 2022· Updated Jun 17, 2026
CVE-2022-28391
CVE-2022-28391
Description
BusyBox through 1.35.0 allows remote attackers to execute arbitrary code if netstat is used to print a DNS PTR record's value to a VT compatible terminal. Alternatively, the attacker could choose to change the terminal's colors.
Affected products
14- osv-coords11 versionspkg:deb/ubuntu/busybox?arch=src?distro=noblepkg:deb/ubuntu/busybox?arch=src?distro=esm-infra/xenialpkg:deb/ubuntu/busybox?arch=src?distro=focalpkg:apk/chainguard/busyboxpkg:apk/wolfi/busyboxpkg:apk/chainguard/busybox-fullpkg:deb/ubuntu/busybox?arch=src?distro=oracularpkg:deb/ubuntu/busybox?arch=src?distro=esm-infra-legacy/trustypkg:deb/ubuntu/busybox?arch=src?distro=esm-infra/bionicpkg:deb/ubuntu/busybox?arch=src?distro=jammypkg:apk/wolfi/busybox-full
>= 0+ 10 more
- (no CPE)range: >= 0
- (no CPE)range: >= 0
- (no CPE)range: >= 0
- (no CPE)range: < 1.35.0-r3
- (no CPE)range: < 1.35.0-r3
- (no CPE)range: < 1.35.0-r3
- (no CPE)range: >= 0
- (no CPE)range: >= 0
- (no CPE)range: >= 0
- (no CPE)range: >= 0
- (no CPE)range: < 1.35.0-r3
Patches
Vulnerability mechanics
References
1- gitlab.alpinelinux.org/alpine/aports/-/issues/13661nvdExploitPatchVendor Advisory
News mentions
0No linked articles in our index yet.