BusyBox
cpe:2.3:a:busybox:busybox:*:*:*:*:*:*:*
- <= 1.37.0
A denial-of-service vulnerability has been identified in the 'netstat' utility of BusyBox versions through 1.37.0. This issue allows local users to disrupt terminal functionality by launching a network application with an argument that includes an ANSI terminal escape sequence. When the victim uses 'netstat', their terminal can become unresponsive.
Exploitation of this vulnerability can lead to a denial-of-service condition, causing the terminal to become unresponsive or 'locked up'.
The vulnerability can be reproduced by using the 'netstat' command in BusyBox versions prior to 1.37.0. A local user must launch a network application with an argument that includes an ANSI escape sequence. When 'netstat' is executed, the terminal will become unresponsive, demonstrating the denial-of-service condition.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.