QID 376047
Date Published: 2021-11-18
QID 376047: BusyBox Information Leak and Denial of Service (DoS) Vulnerability
BusyBox is a software suite of many useful Unix utilities, known as applets, that are packaged as a single executable file. Within BusyBox you can find a full-fledged shell, a DHCP client/server, and small utilities such as cp, ls, grep, and others.
An out-of-bounds heap read in unlzma leads to information leak and denial of service when crafted LZMA-compressed input is decompressed. This can be triggered by any applet/format that internally supports LZMA compression.
Affected Versions:
1.27.0-1.33.1
QID Detection Logic(Authenticated):
This QID checks for the vulnerable versions of BusyBox by checking the version from man page of BusyBox
Successful exploitation of the vulnerability may allow attackers to cause Denial of Service attack.
CVEs related to QID 376047
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| NA |
|