Skip to content

Latest commit

 

History

History
executable file
·
43 lines (29 loc) · 1.58 KB

busybox-hush-null-pointer-dereference-xray-189794.md

File metadata and controls

executable file
·
43 lines (29 loc) · 1.58 KB
description title date_published last_updated xray_id vul_id cvss severity discovered_by type
CVE-2021-42376 Medium severity. A NULL pointer dereference in Busybox hush leads to denial of service when processing malformed command line arguments
BusyBox hush NULL Pointer Dereference
2021-11-09
2021-11-09
XRAY-189794
CVE-2021-42376
5.5
medium
JFrog Collab
vulnerability

Summary

A NULL pointer dereference in Busybox hush leads to denial of service when processing malformed command line arguments

Component

BusyBox

Affected versions

BusyBox [1.33.0, 1.33.1], fixed in 1.34.0

Description

The BusyBox toolkit implements a large number of Linux tools in a single executable and can even replace the Linux init system. Its small size and flexibility make it popular in embedded devices.

A NULL pointer dereference in hush leads to denial of service when processing a crafted shell command, due to missing validation after a \x03 delimiter character. This may be used for DoS under very rare conditions of filtered command input. An attacker that controls hush command line arguments can trigger this issue.

PoC

No PoC is supplied for this issue

Vulnerability Mitigations

No vulnerability mitigations are supplied for this issue

References

(JFrog) Unboxing BusyBox - 14 new vulnerabilities uncovered by Claroty and JFrog

NVD