QID 352276
Date Published: 2021-05-13
QID 352276: Amazon Linux Security Update for busybox: ALAS-2021-1496
<DIV> Issue Overview:
decompress_gunzip.c in BusyBox through 1.32.1 mishandles the error bit on the huft_build result pointer, with a resultant invalid free or segmentation fault, via malformed gzip data. (CVE-2021-28831 )
</DIV>Allows unauthorized disclosure of information; allows unauthorized modification; allows disruption of service.
Solution
Administrators are advised to apply the appropriate software updates.
Vendor References
- ALAS-2021-1496 -
alas.aws.amazon.com/ALAS-2021-1496.html
CVEs related to QID 352276
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| ALAS-2021-1496 | Amazon Linux |
|