Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 918699 (CVE-2023-42363, CVE-2023-42364, CVE-2023-42365, CVE-2023-42366) - sys-apps/busybox: multiple vulnerabilities
Summary: sys-apps/busybox: multiple vulnerabilities
Status: UNCONFIRMED
Alias: CVE-2023-42363, CVE-2023-42364, CVE-2023-42365, CVE-2023-42366
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal
Assignee: Gentoo Security
URL:
Whiteboard: B2 [upstream]
Keywords:
Depends on:
Blocks:
 
Reported: 2023-11-28 16:21 UTC by Jarkko Suominen
Modified: 2023-11-29 07:04 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Jarkko Suominen 2023-11-28 16:21:35 UTC
There are multiple vulnerabilities present in BusyBox v.1.36.1 which is the latest stable version in upstream as well as in the tree.

https://www.cve.org/CVERecord?id=CVE-2023-42363
https://bugs.busybox.net/show_bug.cgi?id=15865 
A use-after-free vulnerability was discovered in xasprintf function in xfuncs_printf.c:344 in BusyBox v.1.36.1.


https://www.cve.org/CVERecord?id=CVE-2023-42364
https://bugs.busybox.net/show_bug.cgi?id=15868
A use-after-free vulnerability in BusyBox v.1.36.1 allows attackers to cause a denial of service via a crafted awk pattern in the awk.c evaluate function.



https://www.cve.org/CVERecord?id=CVE-2023-42365
https://bugs.busybox.net/show_bug.cgi?id=15871
A use-after-free vulnerability was discovered in BusyBox v.1.36.1 via a crafted awk pattern in the awk.c copyvar function.



https://www.cve.org/CVERecord?id=CVE-2023-42366
https://bugs.busybox.net/show_bug.cgi?id=15874
A heap-buffer-overflow was discovered in BusyBox v.1.36.1 in the next_token function at awk.c:1159.


These vulnerabilities have POCs.