CVE-2017-15873
Summary
| CVE | CVE-2017-15873 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-10-24 20:29:00 UTC |
| Updated | 2021-02-18 14:43:00 UTC |
| Description | The get_next_block function in archival/libarchive/decompress_bunzip2.c in BusyBox 1.27.2 has an Integer Overflow that may lead to a write access violation. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [SECURITY] [DLA 1445-1] busybox security update |
MLIST |
lists.debian.org |
Mailing List, Third Party Advisory |
| busybox - BusyBox: The Swiss Army Knife of Embedded Linux |
MISC |
git.busybox.net |
Issue Tracking, Patch, Third Party Advisory |
| USN-3935-1: BusyBox vulnerabilities | Ubuntu security notices | Ubuntu |
UBUNTU |
usn.ubuntu.com |
Third Party Advisory |
| 10431 – (CVE-2017-15873) Bzip2 decompression crashes |
MISC |
bugs.busybox.net |
Exploit, Issue Tracking, Third Party Advisory |
| [SECURITY] [DLA 2559-1] busybox security update |
MLIST |
lists.debian.org |
Mailing List, Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 500077 Alpine Linux Security Update for busybox
- 503753 Alpine Linux Security Update for busybox
- 710218 Gentoo Linux BusyBox Multiple Vulnerabilities (GLSA 201803-12)
- 751624 SUSE Enterprise Linux Security Update for busybox (SUSE-SU-2022:0135-1)
- 751633 OpenSUSE Security Update for busybox (openSUSE-SU-2022:0135-1)
- 752794 SUSE Enterprise Linux Security Update for busybox (SUSE-SU-2022:3959-1)
- 752903 SUSE Enterprise Linux Security Update for busybox (SUSE-SU-2022:4253-1)