CVE-2018-1000500
Summary
| CVE | CVE-2018-1000500 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-06-26 16:29:00 UTC |
| Updated | 2020-09-24 20:15:00 UTC |
| Description | Busybox contains a Missing SSL certificate validation vulnerability in The "busybox wget" applet that can result in arbitrary code execution. This attack appear to be exploitable via Simply download any file over HTTPS using "busybox wget https://compromised-domain.com/important-file". |
Risk And Classification
Problem Types: CWE-295
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| USN-4531-1: BusyBox vulnerability | Ubuntu security notices | Ubuntu | UBUNTU | usn.ubuntu.com | |
| busybox - BusyBox: The Swiss Army Knife of Embedded Linux | CONFIRM | git.busybox.net | Patch, Vendor Advisory |
| [PATCH] wget: don't silently ignore certificate validation | MISC | lists.busybox.net | Mailing List, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 500078 Alpine Linux Security Update for busybox
- 503754 Alpine Linux Security Update for busybox
- 751281 SUSE Enterprise Linux Security Update for busybox (SUSE-SU-2021:3531-1)
- 751290 OpenSUSE Security Update for busybox (openSUSE-SU-2021:3531-1)
- 751304 OpenSUSE Security Update for busybox (openSUSE-SU-2021:1408-1)
- 751624 SUSE Enterprise Linux Security Update for busybox (SUSE-SU-2022:0135-1)
- 751633 OpenSUSE Security Update for busybox (openSUSE-SU-2022:0135-1)
- 752794 SUSE Enterprise Linux Security Update for busybox (SUSE-SU-2022:3959-1)
- 752903 SUSE Enterprise Linux Security Update for busybox (SUSE-SU-2022:4253-1)
- 900072 CBL-Mariner Linux Security Update for busybox 1.31.1
- 903204 Common Base Linux Mariner (CBL-Mariner) Security Update for busybox (3176)