[Bug 15001] New: netstat is vulnerable to escape sequence injection (busybox)

bugzilla at busybox.net bugzilla at busybox.net
Mon Sep 19 15:41:51 UTC 2022


https://bugs.busybox.net/show_bug.cgi?id=15001

            Bug ID: 15001
           Summary: netstat is vulnerable to escape sequence injection
                    (busybox)
           Product: Busybox
           Version: unspecified
          Hardware: All
               URL: https://gitlab.alpinelinux.org/alpine/aports/-/issues/
                    13661
                OS: Linux
            Status: NEW
          Severity: normal
          Priority: P5
         Component: Other
          Assignee: unassigned at busybox.net
          Reporter: ajak at gentoo.org
                CC: busybox-cvs at busybox.net
  Target Milestone: ---

I'm relaying this from Alpine's bug tracker as it seems nobody ever reported
this upstream,

"Hey there,
Alpine ships BusyBox with the netstat applet enabled. This is vulnerable to
escape sequence injection when used from an VT compatible terminal. To exploit
this vulnerability the PTR for a remote host must contain a escape sequence and
the victim has to execute netstat. I've set up an example at [elided] with the
PTR resolving to \027[33\;46mlocalhost.

$ dig -x [elided] @8.8.8.8

; <<>> DiG 9.16.25 <<>> -x [elided] @8.8.8.8
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 59625
;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 1

;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 512
;; QUESTION SECTION:
;[elided]. IN PTR

;; ANSWER SECTION:
[elided]. 1 IN PTR \027[33\;46mlocalhost.

;; Query time: 55 msec
;; SERVER: 8.8.8.8#53(8.8.8.8)
;; WHEN: Sun Apr 03 00:11:16 DST 2022
;; MSG SIZE  rcvd: 132

If you try to ssh [elided] and run netstat -t while trying to establish the
connection from a different terminal, the second terminal will change the
background and font color. Other escape sequences may lead to code execution."

Alpine carries some patches but Ariadne says they're incorrect:

https://bugs.gentoo.org/836920

-- 
You are receiving this mail because:
You are on the CC list for the bug.


More information about the busybox-cvs mailing list