Back to search
CVE-2017-16544
Published: Nov 20, 2017
Modified: Jun 9, 2025
PUBLISHED
Description
In the add_match function in libbb/lineedit.c in BusyBox through 1.27.2, the tab autocomplete feature of the shell, used to get a list of filenames in a directory, does not sanitize filenames and results in executing any escape sequence in the terminal. This could potentially result in code execution, arbitrary file writes, or other attacks.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
[debian-lts-announce] 20180727 [SECURITY] [DLA 1445-1] busybox security update
mailing-list
x_refsource_MLIST
USN-3935-1
vendor-advisory
x_refsource_UBUNTU
20190612 SEC Consult SA-20190612-0 :: Multiple vulnerabilities in WAGO 852 Industrial Managed Switch Series
mailing-list
x_refsource_FULLDISC
20190613 SEC Consult SA-20190612-0 :: Multiple vulnerabilities in WAGO 852 Industrial Managed Switch Series
mailing-list
x_refsource_BUGTRAQ
20190904 SEC Consult SA-20190904-0 :: Multiple vulnerabilities in Cisco router series RV34X, RV26X and RV16X
mailing-list
x_refsource_FULLDISC
20190904 SEC Consult SA-20190904-0 :: Multiple vulnerabilities in Cisco router series RV34X, RV26X and RV16X
mailing-list
x_refsource_BUGTRAQ
http://www.vmware.com/security/advisories/VMSA-2019-0013.html
x_refsource_CONFIRM
20200313 SEC Consult SA-20200312-0 :: Authenticated Command Injection in Phoenix Contact TC Router & TC Cloud Client
mailing-list
x_refsource_FULLDISC
20200827 SEC Consult SA-20200827-0 :: Multiple Vulnerabilities in ZTE mobile Hotspot MS910S
mailing-list
x_refsource_FULLDISC
https://us-cert.cisa.gov/ics/advisories/icsa-20-240-01
x_refsource_MISC
20200902 SEC Consult SA-20200902-0 :: Multiple Vulnerabilities in Red Lion N-Tron 702-W, Red Lion N-Tron 702M12-W
mailing-list
x_refsource_FULLDISC
20210113 SEC Consult SA-20210113-0 :: Multiple vulnerabilities in Pepperl+Fuchs IO-Link Master Series
mailing-list
x_refsource_FULLDISC
[debian-lts-announce] 20210215 [SECURITY] [DLA 2559-1] busybox security update
mailing-list
x_refsource_MLIST
20210819 SEC Consult SA-20210819-0 :: Multiple critical vulnerabilities in Altus Nexto and Hadron series
mailing-list
x_refsource_FULLDISC
20220617 SEC Consult SA-20220615-0 :: Hardcoded Backdoor User and Outdated Software Components in Nexans FTTO GigaSwitch series
mailing-list
x_refsource_FULLDISC
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now