GHSA-wp4q-9jq4-gv74LowCVSS 3.2
In tar in BusyBox through 1.37.0, a TAR archive can have filenames hidden from a listing through...
🔗 CVE IDs covered (1)
📋 Description
In tar in BusyBox through 1.37.0, a TAR archive can have filenames hidden from a listing through the use of terminal escape sequences.
🔗 References (8)
- https://nvd.nist.gov/vuln/detail/CVE-2025-46394
- https://bugs.busybox.net/show_bug.cgi?id=16018
- https://www.busybox.net
- https://www.busybox.net/downloads
- http://www.openwall.com/lists/oss-security/2025/04/23/5
- http://www.openwall.com/lists/oss-security/2025/04/24/3
- https://cert-portal.siemens.com/productcert/html/ssa-253495.html
- https://github.com/advisories/GHSA-wp4q-9jq4-gv74