CVE-2011-5325: Busybox

High severity, CVSS 7.5. EPSS: 7% chance of exploitation in the next 30 days.

Directory traversal vulnerability in the BusyBox implementation of tar before 1.22.0 v5 allows remote attackers to point to files outside the current working directory via a symlink.

Affected products

  • Busybox Busybox: up to and including 1.21.1
  • Canonical Ubuntu Linux: version 14.04 only; version 16.04 only; version 18.04 only; version 18.10 only
  • Debian Debian Linux: version 8.0 only; version 9.0 only

Published 2017-08-07. Last modified 2026-06-16.