QID 352276

Date Published: 2021-05-13

QID 352276: Amazon Linux Security Update for busybox: ALAS-2021-1496

<DIV> Issue Overview:

decompress_gunzip.c in BusyBox through 1.32.1 mishandles the error bit on the huft_build result pointer, with a resultant invalid free or segmentation fault, via malformed gzip data. (CVE-2021-28831 )

</DIV>

Allows unauthorized disclosure of information; allows unauthorized modification; allows disruption of service.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Administrators are advised to apply the appropriate software updates.
    Vendor References

    CVEs related to QID 352276

    Software Advisories
    Advisory ID Software Component Link
    ALAS-2021-1496 Amazon Linux URL Logo alas.aws.amazon.com/ALAS-2021-1496.html