CVE-2025-46394

In tar in BusyBox through 1.37.0, a TAR archive can have filenames hidden from a listing through the use of terminal escape sequences.
Configurations

Configuration 1 (hide)

cpe:2.3:a:busybox:busybox:*:*:*:*:*:*:*:*

History

24 Sep 2025, 14:38

Type Values Removed Values Added
References () https://bugs.busybox.net/show_bug.cgi?id=16018 - () https://bugs.busybox.net/show_bug.cgi?id=16018 - Issue Tracking
References () https://www.busybox.net - () https://www.busybox.net - Product
References () https://www.busybox.net/downloads/ - () https://www.busybox.net/downloads/ - Product
References () http://www.openwall.com/lists/oss-security/2025/04/23/5 - () http://www.openwall.com/lists/oss-security/2025/04/23/5 - Mailing List
References () http://www.openwall.com/lists/oss-security/2025/04/24/3 - () http://www.openwall.com/lists/oss-security/2025/04/24/3 - Mailing List
CPE cpe:2.3:a:busybox:busybox:*:*:*:*:*:*:*:*
First Time Busybox
Busybox busybox

24 Apr 2025, 20:15

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2025/04/24/3 -
Summary
  • (es) En tar en BusyBox hasta 1.37.0, un archivo TAR puede tener nombres de archivo ocultos en una lista mediante el uso de secuencias de escape de terminal.

23 Apr 2025, 23:15

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2025/04/23/5 -

23 Apr 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-23 16:15

Updated : 2025-09-24 14:38


NVD link : CVE-2025-46394

Mitre link : CVE-2025-46394

CVE.ORG link : CVE-2025-46394


JSON object : View

Products Affected

busybox

  • busybox
CWE
CWE-451

User Interface (UI) Misrepresentation of Critical Information