QID 356348

Date Published: 2023-10-18

QID 356348: Amazon Linux Security Advisory for busybox : AL2012-2023-451

Package updates are available for Amazon Linux that fix the following vulnerabilities:
CVE-2022-48174:
There is a stack overflow vulnerability in ash.c:6030 in busybox before 1.35. In the environment of Internet of Vehicles, this vulnerability can be executed from command to arbitrary code execution.

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as Medium - 5.4 severity.
  • Solution
    Administrators are advised to apply the appropriate software updates.
    Vendor References

    CVEs related to QID 356348

    Software Advisories
    Advisory ID Software Component Link
    AL2012-2023-451 Amazon Linux Bare Metal URL Logo docs.aws.amazon.com/AWSEC2/latest/UserGuide/install-updates.html