Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2022:4309-1

Опубликовано: 01 дек. 2022
Источник: suse-cvrf

Описание

Security update for busybox

This update for busybox fixes the following issues:

  • CVE-2022-30065: Fixed use-after-free in the AWK applet (bsc#1199744).

Список пакетов

SUSE Linux Enterprise Module for Basesystem 15 SP3
busybox-1.35.0-150000.4.17.1
busybox-static-1.35.0-150000.4.17.1
openSUSE Leap 15.3
busybox-1.35.0-150000.4.17.1
busybox-static-1.35.0-150000.4.17.1

Описание

A use-after-free in Busybox 1.35-x's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the copyvar function.


Затронутые продукты
SUSE Linux Enterprise Module for Basesystem 15 SP3:busybox-1.35.0-150000.4.17.1
SUSE Linux Enterprise Module for Basesystem 15 SP3:busybox-static-1.35.0-150000.4.17.1
openSUSE Leap 15.3:busybox-1.35.0-150000.4.17.1
openSUSE Leap 15.3:busybox-static-1.35.0-150000.4.17.1

Ссылки