Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-42374

Опубликовано: 15 нояб. 2021
Источник: debian
EPSS Низкий

Описание

An out-of-bounds heap read in Busybox's unlzma applet leads to information leak and denial of service when crafted LZMA-compressed input is decompressed. This can be triggered by any applet/format that

Пакеты

ПакетСтатусВерсия исправленияРелизТип
busyboxfixed1:1.35.0-1package
busyboxnot-affectedstretchpackage

Примечания

  • https://jfrog.com/blog/unboxing-busybox-14-new-vulnerabilities-uncovered-by-claroty-and-jfrog/

  • Crash in CLI tool with information leak

  • Introduced by https://git.busybox.net/busybox/commit/?id=3989e5adf454a3ab98412b249c2c9bd2a3175ae0 (1_27_0)

  • https://git.busybox.net/busybox/commit/?id=04f052c56ded5ab6a904e3a264a73dc0412b2e78

EPSS

Процентиль: 24%
0.00077
Низкий

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 3 лет назад

An out-of-bounds heap read in Busybox's unlzma applet leads to information leak and denial of service when crafted LZMA-compressed input is decompressed. This can be triggered by any applet/format that

CVSS3: 5.7
redhat
больше 3 лет назад

An out-of-bounds heap read in Busybox's unlzma applet leads to information leak and denial of service when crafted LZMA-compressed input is decompressed. This can be triggered by any applet/format that

CVSS3: 5.3
nvd
больше 3 лет назад

An out-of-bounds heap read in Busybox's unlzma applet leads to information leak and denial of service when crafted LZMA-compressed input is decompressed. This can be triggered by any applet/format that

CVSS3: 5.3
msrc
больше 3 лет назад

Описание отсутствует

CVSS3: 5.3
github
около 3 лет назад

An out-of-bounds heap read in Busybox's unlzma applet leads to information leak and denial of service when crafted LZMA-compressed input is decompressed. This can be triggered by any applet/format that

EPSS

Процентиль: 24%
0.00077
Низкий