Описание
A use-after-free vulnerability was discovered in xasprintf function in xfuncs_printf.c:344 in BusyBox v.1.36.1.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| busybox | fixed | 1:1.37.0-1 | package | |
| busybox | no-dsa | bookworm | package | |
| busybox | ignored | bullseye | package | |
| busybox | ignored | buster | package |
Примечания
https://bugs.busybox.net/show_bug.cgi?id=15865
The above ticket contains a poc, poc triggers on bookworm but not on bullseye.
The poc starts triggering with https://git.busybox.net/busybox/commit/?id=a885ce1af05c4eaa5ebcf883cb3da3433ca1c48b (1_34_0)
https://git.busybox.net/busybox/commit/?id=fb08d43d44d1fea1f741fafb9aa7e1958a5f69aa (1_37_0)
Связанные уязвимости
A use-after-free vulnerability was discovered in xasprintf function in xfuncs_printf.c:344 in BusyBox v.1.36.1.
A use-after-free vulnerability was discovered in xasprintf function in xfuncs_printf.c:344 in BusyBox v.1.36.1.
A use-after-free vulnerability was discovered in xasprintf function in xfuncs_printf.c:344 in BusyBox v.1.36.1.
A use-after-free vulnerability was discovered in xasprintf function in xfuncs_printf.c:344 in BusyBox v.1.36.1.