CVE-2017-16544 - CVE House
Back to Database
Status published Unknown CVE-2017-16544

In the add_match function in libbb/lineedit.c in BusyBox through 1.27.2,...

Vulnerability Description

In the add_match function in libbb/lineedit.c in BusyBox through 1.27.2, the tab autocomplete feature of the shell, used to get a list of filenames in a directory, does not sanitize filenames and results in executing any escape sequence in the terminal. This could potentially result in code execution, arbitrary file writes, or other attacks.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2017-16544

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

busybox, debian linux, esxi, n-tron 702-w firmware, n-tron 702m12-w firmware, ubuntu linux
Vulnerable Versions:
0, 8.0, 9.0, 6.0, 6.5, 6.7, 14.04, 16.04

Timeline

Official Publish: November 20th, 2017
Last Modified: June 9th, 2025
Added to House: July 20th, 2026

CVSS Vectors

No vector data available

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.