Updated busybox packages fix security vulnerability
Publication date: 09 Apr 2022Modification date: 09 Apr 2022
Type: security
Affected Mageia releases : 8
CVE: CVE-2022-28391
Description
BusyBox through 1.35.0 allows remote attackers to execute arbitrary code if netstat is used to print a DNS PTR record's value to a VT compatible terminal. Alternatively, the attacker could choose to change the terminal's colors. (CVE-2022-28391)
References
SRPMS
8/core
- busybox-1.34.1-1.1.mga8