Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-42386

Опубликовано: 09 нояб. 2021
Источник: redhat
CVSS3: 6.6
EPSS Низкий

Описание

A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the nvalloc function

A flaw was found in BusyBox, where it did not properly sanitize while processing a crafted awk pattern in the nvalloc function, leading to possible code execution. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.

Отчет

Attack complexity is High because it's only exploited with a specially crafted awk pattern under rare conditions.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6busyboxNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-416
https://bugzilla.redhat.com/show_bug.cgi?id=2023938busybox: use-after-free in awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the nvalloc()

EPSS

Процентиль: 41%
0.00183
Низкий

6.6 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.2
ubuntu
больше 3 лет назад

A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the nvalloc function

CVSS3: 7.2
nvd
больше 3 лет назад

A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the nvalloc function

CVSS3: 7.2
msrc
больше 3 лет назад

Описание отсутствует

CVSS3: 7.2
debian
больше 3 лет назад

A use-after-free in Busybox's awk applet leads to denial of service an ...

CVSS3: 7.2
github
около 3 лет назад

A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the nvalloc function

EPSS

Процентиль: 41%
0.00183
Низкий

6.6 Medium

CVSS3