Alpaquita LinuxStreamSecurity Advisory
Search Cve

CVE-2025-46394

Published: April 25, 2025Last modified: June 5, 2025

Description

In tar in BusyBox through 1.37.0, a TAR archive can have filenames hidden from a listing through the use of terminal escape sequences.

Severity score breakdown

ParameterValue
Base score3.2
Attack VectorLOCAL
Attack complexityHIGH
Privileges requiredNONE
User interactionNONE
ScopeCHANGED
ConfidentialityNONE
Integrity impactLOW
Availability impactNONE
VectorCVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSbusyboxUnknown (1.35.0-r29)
StreambusyboxUnknown (1.36.1-r1)

References

ON THIS PAGE