CVE Database
/

CVE-2017-16544

Back to search

CVE-2017-16544

Published: Nov 20, 2017

Modified: Jun 9, 2025

PUBLISHED

Description

In the add_match function in libbb/lineedit.c in BusyBox through 1.27.2, the tab autocomplete feature of the shell, used to get a list of filenames in a directory, does not sanitize filenames and results in executing any escape sequence in the terminal. This could potentially result in code execution, arbitrary file writes, or other attacks.

VendorProductVersions

n/a

n/a

affected
n/a

References

USN-3935-1
vendor-advisory
x_refsource_UBUNTU

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now