CVE-2025-46394

ADVISORY - nist

Summary

In tar in BusyBox through 1.37.0, a TAR archive can have filenames hidden from a listing through the use of terminal escape sequences.

EPSS Score: 0.00031 (0.085)

Common Weakness Enumeration (CWE)

ADVISORY - nist

User Interface (UI) Misrepresentation of Critical Information


Alpine

CREATED

UPDATED

EXPLOITABILITY SCORE

-

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
RATING UNAVAILABLE FROM ADVISORY
PackageTypeOS NameOS VersionAffected RangesFix Versions
alpine/busyboxapkalpine3.22<1.37.0-r201.37.0-r20
alpine/busyboxapkalpine3.20<1.36.1-r311.36.1-r31
alpine/busyboxapkalpine3.21<1.37.0-r141.37.0-r14
alpine/busyboxapkalpine3.23<1.37.0-r271.37.0-r27
alpine/busyboxapkalpineedge<1.37.0-r271.37.0-r27
alpine/busyboxapkalpine3.24<1.37.0-r271.37.0-r27

Severity and metrics

No CVSS data available from this advisory.

NIST

CREATED

UPDATED

EXPLOITABILITY SCORE

1.4

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)

CVSS SCORE

3.2low

Debian

CREATED

UPDATED

EXPLOITABILITY SCORE

-

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
RATING UNAVAILABLE FROM ADVISORY

Ubuntu

CREATED

UPDATED

EXPLOITABILITY SCORE

1.8

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-

CVSS SCORE

3.3medium

Chainguard

CREATED

UPDATED

ADVISORY ID

CGA-jrx7-26c9-jxcv

EXPLOITABILITY SCORE

-

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
RATING UNAVAILABLE FROM ADVISORY

Chainguard

CREATED

UPDATED

ADVISORY ID

CGA-wj2c-v25v-c33q

EXPLOITABILITY SCORE

-

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
RATING UNAVAILABLE FROM ADVISORY

minimos

CREATED

UPDATED

ADVISORY ID

MINI-7xq4-37v3-672q

EXPLOITABILITY SCORE

-

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
RATING UNAVAILABLE FROM ADVISORY