CVE-2024-58251 Details
Description
In netstat in BusyBox through 1.37.0, local users can launch of network application with an argv[0] containing an ANSI terminal escape sequence, leading to a denial of service (terminal locked up) when netstat is used by a victim.
A denial-of-service vulnerability has been identified in the 'netstat' utility of BusyBox versions through 1.37.0. This issue allows local users to disrupt terminal functionality by launching a network application with an argument that includes an ANSI terminal escape sequence. When the victim uses 'netstat', their terminal can become unresponsive.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Apr 23, 2025CISA-ADP
Assessed Apr 23, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2025/04/23/6 | CVE | Mailing ListTechnical Description |
| https://bugs.busybox.net/show_bug.cgi?id=15922 | [email protected] | Broken LinkIssue TrackingVendor |
| https://www.busybox.net | [email protected] | Vendor |
| https://www.busybox.net/downloads/ | [email protected] | ProductVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-150 | Improper Neutralization of Escape, Meta, or Control Sequences | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| BusyBox | <= 1.37.0 (semver) |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 23, 2025 | CVE Modified | CVE |
| Apr 23, 2025 | New CVE Received | [email protected] |
Volerion