Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 918699 (CVE-2023-42363, CVE-2023-42364, CVE-2023-42365, CVE-2023-42366)

Summary: sys-apps/busybox: multiple vulnerabilities
Product: Gentoo Security Reporter: Jarkko Suominen <bugzillas>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: UNCONFIRMED ---    
Severity: normal CC: ceamac, embedded
Priority: Normal    
Version: unspecified   
Hardware: All   
OS: Linux   
Whiteboard: B2 [upstream]
Package list:
Runtime testing required: ---

Description Jarkko Suominen 2023-11-28 16:21:35 UTC
There are multiple vulnerabilities present in BusyBox v.1.36.1 which is the latest stable version in upstream as well as in the tree.

https://www.cve.org/CVERecord?id=CVE-2023-42363
https://bugs.busybox.net/show_bug.cgi?id=15865 
A use-after-free vulnerability was discovered in xasprintf function in xfuncs_printf.c:344 in BusyBox v.1.36.1.


https://www.cve.org/CVERecord?id=CVE-2023-42364
https://bugs.busybox.net/show_bug.cgi?id=15868
A use-after-free vulnerability in BusyBox v.1.36.1 allows attackers to cause a denial of service via a crafted awk pattern in the awk.c evaluate function.



https://www.cve.org/CVERecord?id=CVE-2023-42365
https://bugs.busybox.net/show_bug.cgi?id=15871
A use-after-free vulnerability was discovered in BusyBox v.1.36.1 via a crafted awk pattern in the awk.c copyvar function.



https://www.cve.org/CVERecord?id=CVE-2023-42366
https://bugs.busybox.net/show_bug.cgi?id=15874
A heap-buffer-overflow was discovered in BusyBox v.1.36.1 in the next_token function at awk.c:1159.


These vulnerabilities have POCs.