A NULL pointer dereference in Busybox's hush applet leads to denial of service when processing a crafted shell command, due to missing validation after a \x03 delimiter character. This may be used for DoS under very rare conditions of filtered command input.
References
| Link | Resource |
|---|---|
| https://jfrog.com/blog/unboxing-busybox-14-new-vulnerabilities-uncovered-by-claroty-and-jfrog/ | Third Party Advisory |
| https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6T2TURBYYJGBMQTTN2DSOAIQGP7WCPGV/ | Mailing List Third Party Advisory |
| https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UQXGOGWBIYWOIVXJVRKHZR34UMEHQBXS/ | Mailing List Third Party Advisory |
| https://security.netapp.com/advisory/ntap-20211223-0002/ |
Information
Published : 2021-11-15 21:15
Updated : 2021-12-23 13:15
NVD link : CVE-2021-42376
Mitre link : CVE-2021-42376
JSON object : View
Products Affected
fedoraproject
- fedora
busybox
- busybox
CWE
CWE-476
NULL Pointer Dereference
