QID 376044
Date Published: 2021-11-18
QID 376044: BusyBox Denial of Service (DoS) Vulnerability
BusyBox is a software suite of many useful Unix utilities, known as applets, that are packaged as a single executable file. Within BusyBox you can find a full-fledged shell, a DHCP client/server, and small utilities such as cp, ls, grep, and others.
A NULL pointer dereference in man leads to denial of service when a section name is supplied but no page argument is given.
Affected Versions:
1.33.0-1.33.1
QID Detection Logic(Authenticated):
This QID checks for the vulnerable versions of BusyBox by checking the version from man page of BusyBox
Successful exploitation of the vulnerability may allow attackers to cause Denial of Service attack.
Solution
Customers are advised to update to BusyBox version 1.34.0 or later, for more info please refer here
Vendor References
CVEs related to QID 376044
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| NA |
|