BusyBox Local Netlink Mishandling Vulnerability
BID:10350
Info
BusyBox Local Netlink Mishandling Vulnerability
| Bugtraq ID: | 10350 |
| Class: | Unknown |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | May 14 2004 12:00AM |
| Updated: | May 14 2004 12:00AM |
| Credit: | This issue was disclosed in the 'pending vulnerabilities' section of the referenced SuSE 'mc' advisory. |
| Vulnerable: |
BusyBox Linux Utilities 1.0 pre9 BusyBox Linux Utilities 1.0 pre8 BusyBox Linux Utilities 1.0 pre10 |
| Not Vulnerable: | |
Discussion
BusyBox Local Netlink Mishandling Vulnerability
BusyBox is reportedly affected by a local vulnerability due to the mishandling of netlink connections. This is most likely caused by a design error that fails to validate the origin of netlink messages.
This issue could allow an attacker to spoof netlink messages to the BusyBox process.
BusyBox is reportedly affected by a local vulnerability due to the mishandling of netlink connections. This is most likely caused by a design error that fails to validate the origin of netlink messages.
This issue could allow an attacker to spoof netlink messages to the BusyBox process.
Exploit / POC
BusyBox Local Netlink Mishandling Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
BusyBox Local Netlink Mishandling Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
BusyBox Local Netlink Mishandling Vulnerability
References:
References: