CVE-2024-58251 — Improper Neutralization of Escape, Meta, or Control Sequences in Busybox
Severity
2.5LOWNVD
EPSS
0.1%
top 76.59%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 23
Description
In netstat in BusyBox through 1.37.0, local users can launch of network application with an argv[0] containing an ANSI terminal escape sequence, leading to a denial of service (terminal locked up) when netstat is used by a victim.
CVSS vector
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:LExploitability: 1.0 | Impact: 1.4
Affected Packages14 packages
🔴Vulnerability Details
2📋Vendor Advisories
2Microsoft▶
In netstat in BusyBox through 1.37.0, local users can launch of network application with an argv[0] containing an ANSI terminal escape sequence, leading to a denial of service (terminal locked up) whe↗2025-04-08
Debian▶
CVE-2024-58251: busybox - In netstat in BusyBox through 1.37.0, local users can launch of network applicat...↗2024