QID 376054

Date Published: 2021-11-18

QID 376054: BusyBox Denial of Service (DoS) Vulnerability

BusyBox is a software suite of many useful Unix utilities, known as applets, that are packaged as a single executable file. Within BusyBox you can find a full-fledged shell, a DHCP client/server, and small utilities such as cp, ls, grep, and others.

A NULL pointer dereference in hush leads to denial of service when processing a crafted shell command, due to missing validation after a \x03 delimiter character. This may be used for DoS under very rare conditions of filtered command input.

Affected Versions:
1.16-1.31.1

QID Detection Logic(Authenticated):
This QID checks for the vulnerable versions of BusyBox by checking the version from man page of BusyBox

Successful exploitation of the vulnerability may allow attackers to cause Denial of Service attack.

  • CVSS V3 rated as Medium - 5.5 severity.
  • CVSS V2 rated as Low - 1.9 severity.
  • Solution
    Customers are advised to update to BusyBox version 1.34.0 or later, for more info please refer here

    CVEs related to QID 376054

    Software Advisories
    Advisory ID Software Component Link
    NA URL Logo busybox.net/