Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-42377

Опубликовано: 15 нояб. 2021
Источник: debian
EPSS Низкий

Описание

An attacker-controlled pointer free in Busybox's hush applet leads to denial of service and possible code execution when processing a crafted shell command, due to the shell mishandling the &&& string. This may be used for remote code execution under rare conditions of filtered command input.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
busyboxfixed1:1.35.0-1package

Примечания

  • https://jfrog.com/blog/unboxing-busybox-14-new-vulnerabilities-uncovered-by-claroty-and-jfrog/

  • CONFIG_HUSH is not set to build hush

EPSS

Процентиль: 82%
0.01858
Низкий

Связанные уязвимости

CVSS3: 9.8
ubuntu
почти 4 года назад

An attacker-controlled pointer free in Busybox's hush applet leads to denial of service and possible code execution when processing a crafted shell command, due to the shell mishandling the &&& string. This may be used for remote code execution under rare conditions of filtered command input.

CVSS3: 6.4
redhat
почти 4 года назад

An attacker-controlled pointer free in Busybox's hush applet leads to denial of service and possible code execution when processing a crafted shell command, due to the shell mishandling the &&& string. This may be used for remote code execution under rare conditions of filtered command input.

CVSS3: 9.8
nvd
почти 4 года назад

An attacker-controlled pointer free in Busybox's hush applet leads to denial of service and possible code execution when processing a crafted shell command, due to the shell mishandling the &&& string. This may be used for remote code execution under rare conditions of filtered command input.

CVSS3: 9.8
github
больше 3 лет назад

An attacker-controlled pointer free in Busybox's hush applet leads to denial of service and possible code execution when processing a crafted shell command, due to the shell mishandling the &&& string. This may be used for remote code execution under rare conditions of filtered command input.

CVSS3: 9.8
fstec
почти 4 года назад

Уязвимость набора утилит командной строки BusyBox, связанная с освобождением неверного указателя, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 82%
0.01858
Низкий