First published: Wed Apr 23 2025(Updated: )
In tar in BusyBox through 1.37.0, a TAR archive can have filenames hidden from a listing through the use of terminal escape sequences.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
BusyBox | <=1.37.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-46394 is considered a medium severity vulnerability due to its potential to obscure filenames in TAR archives.
To fix CVE-2025-46394, upgrade BusyBox to version 1.38.0 or later.
CVE-2025-46394 affects the 'tar' utility in BusyBox versions up to and including 1.37.0.
CVE-2025-46394 is a filename disclosure vulnerability that can hide filenames in TAR archives.
CVE-2025-46394 is not classified as a remote exploit but can affect local TAR archive listings.