Advisories ยป MGASA-2022-0135

Updated busybox packages fix security vulnerability

Publication date: 09 Apr 2022
Modification date: 09 Apr 2022
Type: security
Affected Mageia releases : 8
CVE: CVE-2022-28391

Description

BusyBox through 1.35.0 allows remote attackers to execute arbitrary code
if netstat is used to print a DNS PTR record's value to a VT compatible
terminal. Alternatively, the attacker could choose to change the
terminal's colors. (CVE-2022-28391)
                

References

SRPMS

8/core