QID 198599

Date Published: 2021-12-09

QID 198599: Ubuntu Security Notification for BusyBox Vulnerabilities (USN-5179-1)

Busybox incorrectly handled certain malformed gziparchives.
Busybox incorrectly handled certain malformed lzmaarchives.
Busybox incorrectly handled certain awk patterns.

If a user or automated system were tricked into processing aspecially crafted gzip archive, a remote attacker could use this issue tocause busybox to crash, resulting in a denial of service, or possiblyexecute arbitrary code.
If a user or automated system were tricked into processing aspecially crafted lzma archive, a remote attacker could use this issue tocause busybox to crash, resulting in a denial of service, or possiblyleak sensitive information.
If a useror automated system were tricked into processing a specially crafted awkpattern, a remote attacker could use this issue to cause busybox to crash,resulting in a denial of service, or possibly execute arbitrary code.
(cve-2021-42378, cve-2021-42379, cve-2021-42380, cve-2021-42381,cve-2021-42382, cve-2021-42384, cve-2021-42385, cve-2021-42386).

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as High - 6.5 severity.
  • Solution
    Refer to Ubuntu security advisory USN-5179-1 for updates and patch information.
    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    USN-5179-1 Ubuntu Linux URL Logo ubuntu.com/security/notices/USN-5179-1