CVE-2022-48174
Summary
| CVE | CVE-2022-48174 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-08-22 19:16:00 UTC |
| Updated | 2023-08-28 18:53:00 UTC |
| Description | There is a stack overflow vulnerability in ash.c:6030 in busybox before 1.35. In the environment of Internet of Vehicles, this vulnerability can be executed from command to arbitrary code execution. |
Risk And Classification
Problem Types: CWE-787
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 15216 – There is a stack overflower in ash of busybox. Here is asan report. | MISC | bugs.busybox.net | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 160979 Oracle Enterprise Linux Security Update for busybox (ELSA-2023-5178)
- 356156 Amazon Linux Security Advisory for busybox : ALAS-2023-1832
- 356348 Amazon Linux Security Advisory for busybox : AL2012-2023-451
- 390289 Oracle Managed Virtualization (VM) for x86 Security Update for busybox (OVMSA-2023-5178)
- 505857 Alpine Linux Security Update for busybox
- 673516 EulerOS Security Update for busybox (EulerOS-SA-2023-2873)
- 673669 EulerOS Security Update for busybox (EulerOS-SA-2023-2892)
- 673704 EulerOS Security Update for busybox (EulerOS-SA-2023-3002)
- 673918 EulerOS Security Update for busybox (EulerOS-SA-2023-3025)
- 674068 EulerOS Security Update for busybox (EulerOS-SA-2023-3201)
- 674096 EulerOS Security Update for busybox (EulerOS-SA-2023-3166)
- 754907 SUSE Enterprise Linux Security Update for busybox (SUSE-SU-2023:3729-1)
- 754970 SUSE Enterprise Linux Security Update for busybox (SUSE-SU-2023:3820-1)
- 754971 SUSE Enterprise Linux Security Update for busybox (SUSE-SU-2023:3819-1)