QID 376048
Date Published: 2021-11-18
QID 376048: BusyBox Denial of Service (DoS) Vulnerability
BusyBox is a software suite of many useful Unix utilities, known as applets, that are packaged as a single executable file. Within BusyBox you can find a full-fledged shell, a DHCP client/server, and small utilities such as cp, ls, grep, and others.
An incorrect handling of a special element in ash leads to denial of service when processing a crafted shell command, due to the shell mistaking specific characters for reserved characters. This may be used for DoS under rare conditions of filtered command input.
Affected Versions:
BusyBox version 1.33.1
QID Detection Logic(Authenticated):
This QID checks for the vulnerable versions of BusyBox by checking the version from man page of BusyBox
Successful exploitation of the vulnerability may allow attackers to cause Denial of Service attack.
CVEs related to QID 376048
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| NA |
|