[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Bug#882258: marked as done (busybox: CVE-2017-16544: lineedit: do not tab-complete any strings which have control characters)



Your message dated Mon, 5 Feb 2018 11:52:28 +0100
with message-id <2b90d242-8ede-d5dd-fa98-7a9e9aa6db99@debian.org>
and subject line Re: Bug#882258: busybox: CVE-2017-16544: lineedit: do not tab-complete any strings which have control characters
has caused the Debian Bug report #882258,
regarding busybox: CVE-2017-16544: lineedit: do not tab-complete any strings which have control characters
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact owner@bugs.debian.org
immediately.)


-- 
882258: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=882258
Debian Bug Tracking System
Contact owner@bugs.debian.org with problems
--- Begin Message ---
Source: busybox
Version: 1:1.27.2-1
Severity: grave
Tags: security

Hi,

the following vulnerability was published for busybox. I realize you
know of the issue already but just filling to have a tracking bug as
well in the BTS.

CVE-2017-16544[0]:
| In the add_match function in libbb/lineedit.c in BusyBox through
| 1.27.2, the tab autocomplete feature of the shell, used to get a list
| of filenames in a directory, does not sanitize filenames and results in
| executing any escape sequence in the terminal. This could potentially
| result in code execution, arbitrary file writes, or other attacks.

If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2017-16544
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-16544
[1] https://git.busybox.net/busybox/commit/?id=c3797d40a1c57352192c6106cc0f435e7d9c11e8

Please adjust the affected versions in the BTS as needed, only
unstable checked so far.

Regards,
Salvatore

--- End Message ---
--- Begin Message ---
Version: 1:1.27.2-2

Hi Salvatore,

This was fixed in the last upload of busybox but the bug wasn't closed,
sorry. I see that the security tracker has been updated already, though.

Cheers,
Chris

-- 
Chris Boot
bootc@debian.org

Attachment: signature.asc
Description: OpenPGP digital signature


--- End Message ---

Reply to: