VYPR

rpm package

suse/busybox&distro=SUSE Linux Enterprise Server 15 SP6-LTSS

pkg:rpm/suse/busybox&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP6-LTSS

Vulnerabilities (4)

  • CVE-2026-26158HigFeb 11, 2026
    affected < 1.37.0-150500.10.17.1fixed 1.37.0-150500.10.17.1

    A flaw was found in BusyBox. This vulnerability allows an attacker to modify files outside of the intended extraction directory by crafting a malicious tar archive containing unvalidated hardlink or symlink entries. If the tar archive is extracted with elevated privileges, this f

  • CVE-2026-26157HigFeb 11, 2026
    affected < 1.37.0-150500.10.17.1fixed 1.37.0-150500.10.17.1

    A flaw was found in BusyBox. Incomplete path sanitization in its archive extraction utilities allows an attacker to craft malicious archives that when extracted, and under specific conditions, may write to files outside the intended directory. This can lead to arbitrary file over

  • CVE-2025-60876MedNov 10, 2025
    affected < 1.37.0-150500.10.14.1fixed 1.37.0-150500.10.14.1

    BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target

  • CVE-2025-46394LowApr 23, 2025
    affected < 1.37.0-150500.10.14.1fixed 1.37.0-150500.10.14.1

    In tar in BusyBox through 1.37.0, a TAR archive can have filenames hidden from a listing through the use of terminal escape sequences.