PT-2018-3813 · Busybox+5 · Busybox+5

Jakub Jirutka

·

Publicado

2018-05-19

·

Atualizado

2024-06-15

·

CVE-2018-1000500

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Busybox (affected versions not specified)
Description The issue is related to a missing SSL certificate validation in the "busybox wget" applet, which can lead to arbitrary code execution. This can be exploited by downloading a file over HTTPS using a compromised domain. The vulnerability may allow a remote attacker to access confidential data, compromise its integrity, and cause a denial of service.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Certificate Validation

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2022-05678
CVE-2018-1000500
ECHO-76F9-203F-42FD
MGASA-2021-0009
OPENSUSE-SU-2021:1408-1
OPENSUSE-SU-2021:3531-1
OPENSUSE-SU-2021_1408-1
OPENSUSE-SU-2021_3531-1
OPENSUSE-SU-2022:0135-1
OPENSUSE-SU-2022_0135-1
OPENSUSE-SU-2022_3959-1
OPENSUSE-SU-2024:11738-1
SUSE-SU-2021:3531-1
SUSE-SU-2022:0135-1
SUSE-SU-2022:0135-2
SUSE-SU-2022:3959-1
SUSE-SU-2022:4253-1
USN-4531-1

Produtos afetados

Astra Linux
Busybox
Debian
Linuxmint
Suse
Ubuntu