PT-2013-1202 · Busybox+2 · Busybox+2

Publicado

2013-11-20

·

Atualizado

2021-02-15

·

CVE-2013-1813

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions BusyBox versions prior to 1.21.0
Description The issue in BusyBox allows local users to have unknown impact and attack vectors due to the use of 0777 permissions for parent directories when creating nested directories under /dev/. Additionally, multiple vulnerabilities in BusyBox before version 1.21.0 may lead to a breach of confidentiality, integrity, and availability of protected information, and these vulnerabilities can be exploited remotely.
Recommendations For versions prior to 1.21.0, update to version 1.21.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the /dev/ directory to minimize the risk of exploitation. Avoid using the mdev.c functionality in BusyBox until the issue is resolved.

Exploit

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-09676
CESA-2013_1732
CVE-2013-1813
DLA-1445-1
DLA-2559-1
MGASA-2013-0358
RHSA-2013:1732
RHSA-2013_1732

Produtos afetados

Busybox
Centos
Red Hat