First published: Wed Apr 23 2025(Updated: )
In netstat in BusyBox through 1.37.0, local users can launch of network application with an argv[0] containing an ANSI terminal escape sequence, leading to a denial of service (terminal locked up) when netstat is used by a victim.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
BusyBox | <1.37.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-58251 has a moderate severity level as it can cause denial of service leading to terminal lockup.
To fix CVE-2024-58251, upgrade BusyBox to version 1.37.0 or later.
The impact of CVE-2024-58251 is that local users can disrupt network application usage by causing terminal lockups.
CVE-2024-58251 affects users of BusyBox's netstat version 1.37.0 and earlier.
No, CVE-2024-58251 requires local access to exploit the vulnerability.