Back

HIGH

busybox: Insufficient sanitization of filenames when autocompleting

Published Nov 20, 2017

Description

In the add_match function in libbb/lineedit.c in BusyBox through 1.27.2, the tab autocomplete feature of the shell, used to get a list of filenames in a directory, does not sanitize filenames and results in executing any escape sequence in the terminal. This could potentially result in code execution, arbitrary file writes, or other attacks.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (24)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Nov 20, 2017
Updated Jun 9, 2025
Reserved Nov 5, 2017
CISA Vulnrichment
Updated Jun 9, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Nov 8, 2017