F5-K000152680: Low severity F5 BIG-IP Next SPK vulnerability
In netstat in BusyBox through 1.37.0, local users can launch of network application with an argv[0] containing an ANSI terminal escape sequence, leading to a denial of service (terminal locked up) when netstat is used by a victim.
Affected Software
Event History
Frequently Asked Questions
What is the severity of F5-K000152680?
The severity of F5-K000152680 is considered high due to its potential to cause a denial of service by locking up the terminal.
How do I fix F5-K000152680?
To fix F5-K000152680, update to the latest version of the affected F5 BIG-IP Next products as specified in the advisory.
Who is affected by F5-K000152680?
Users of specific versions of F5 BIG-IP Next SPK, CNF, and for Kubernetes are affected by F5-K000152680.
What causes the issue in F5-K000152680?
The issue in F5-K000152680 is caused by local users launching network applications with an argv[0] containing an ANSI terminal escape sequence.
Can F5-K000152680 be exploited remotely?
F5-K000152680 requires local access to exploit, making it less of a concern for remote attacks.