CVE-2024-58251
LOWBusyBox < 1.37.0 - Denial of Service via ANSI Terminal Escape Sequence in netstat
Title source: llmDescription
In netstat in BusyBox through 1.37.0, local users can launch of network application with an argv[0] containing an ANSI terminal escape sequence, leading to a denial of service (terminal locked up) when netstat is used by a victim.
References (4)
Core 4
Core References
Various Sources
https://bugs.busybox.net/show_bug.cgi?id=15922
Various Sources
https://www.busybox.net
Various Sources
https://www.busybox.net/downloads/
Scores
CVSS v3
2.5
EPSS
0.0017
EPSS Percentile
6.7%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-150
Status
published
Products (1)
BusyBox/BusyBox
< 1.37.0
Published
Apr 23, 2025
Tracked Since
Feb 18, 2026