Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2022-28391
Description:BusyBox through 1.35.0 allows remote attackers to execute arbitrary code if netstat is used to print a DNS PTR record's value to a VT compatible terminal. Alternatively, the attacker could choose to change the terminal's colors.
Test IDs: 1.3.6.1.4.1.25623.1.1.2.2022.1958   1.3.6.1.4.1.25623.1.1.2.2022.2151   1.3.6.1.4.1.25623.1.1.2.2022.2126   1.3.6.1.4.1.25623.1.1.2.2022.1988   1.3.6.1.4.1.25623.1.1.10.2022.0135  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2022-28391
https://git.alpinelinux.org/aports/plain/main/busybox/0001-libbb-sockaddr2str-ensure-only-printable-characters-.patch
https://git.alpinelinux.org/aports/plain/main/busybox/0002-nslookup-sanitize-all-printed-strings-with-printable.patch
https://gitlab.alpinelinux.org/alpine/aports/-/issues/13661




© 1998-2025 E-Soft Inc. All rights reserved.