Files
poky/meta/recipes-core
Steve Sakoman d68406497e busybox: fix CVE-2022-28391
BusyBox through 1.35.0 allows remote attackers to execute arbitrary code
if netstat is used to print a DNS PTR record's value to a VT compatible
terminal. Alternatively, the attacker could choose to change the terminal's colors.

https://nvd.nist.gov/vuln/detail/CVE-2022-28391

Backported from kirkstone 3e17df4cd17c132dc7732ebd3d1c80c81c85bcc4.
2nd patch adjusted to apply on 1.31.1.

(From OE-Core rev: 0b9cbcc4ceac3938afd1dd6010ce6d9a3da21598)

Signed-off-by: Steve Sakoman <steve@sakoman.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
Signed-off-by: Martin Jansa <Martin.Jansa@gmail.com>
Signed-off-by: Steve Sakoman <steve@sakoman.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
2022-05-14 20:26:34 +01:00
..
2022-05-14 20:26:34 +01:00
2021-09-14 17:27:42 +01:00
2021-12-30 16:59:16 +00:00
2022-03-09 17:30:48 +00:00
2015-01-23 11:36:27 +00:00
2018-09-04 11:03:55 +01:00
2022-01-22 17:56:52 +00:00
2021-12-08 20:28:01 +00:00
2021-08-26 08:32:18 +01:00
2022-04-01 23:22:43 +01:00