Описание
A stack overflow in the evaluate() function (editors/awk.c) of BusyBox commit 371fe9 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script.
A flaw was found in BusyBox. This vulnerability, a stack overflow in the evaluate() function, allows a remote attacker to cause a Denial of Service (DoS) by providing a specially crafted AWK script. A Denial of Service attack can make the affected system or application unavailable to legitimate users.
Отчет
This Moderate flaw in BusyBox's AWK interpreter allows a denial of service. An attacker could provide a specially crafted AWK script, leading to a stack overflow and making the BusyBox instance unresponsive. This vulnerability primarily affects systems where BusyBox is configured to execute untrusted AWK scripts, limiting its broader impact.
Меры по смягчению последствий
For systems utilizing BusyBox, limit exposure by avoiding the execution of untrusted AWK scripts. Ensure that BusyBox instances are not configured to process arbitrary or untrusted AWK script input, particularly in environments where BusyBox is used for critical system functions.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 6 | busybox | Out of support scope | ||
| Red Hat Hardened Images | busybox-main-1.37.0-8.2.hum1 | Fixed | RHSA-2026:42074 | 20.07.2026 |
Показывать по
Дополнительная информация
Статус:
6.5 Medium
CVSS3
Связанные уязвимости
A stack overflow in the evaluate() function (editors/awk.c) of BusyBox commit 371fe9 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script.
A stack overflow in the evaluate() function (editors/awk.c) of BusyBox commit 371fe9 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script.
A stack overflow in the evaluate() function (editors/awk.c) of BusyBox commit 371fe9 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script.
A stack overflow in the evaluate() function (editors/awk.c) of BusyBox ...
A stack overflow in the evaluate() function (editors/awk.c) of BusyBox commit 371fe9 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script.
6.5 Medium
CVSS3