PT-2019-5460 · Busybox+2 · Busybox+2
Denys Vlasenko
·
Publicado
2019-01-09
·
Atualizado
2024-06-15
·
CVE-2019-5747
CVSS v2.0
7.8
Alta
| Vetor | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
BusyBox versions prior to 1.30.1
Description
An issue in the udhcp component of BusyBox might allow a remote attacker to leak sensitive information from the stack by sending a crafted DHCP message. This is due to an out of bounds read when decoding DHCP SUBNET, related to an incomplete fix for a previous issue. The vulnerability is associated with a buffer read beyond its boundaries in memory, potentially allowing an unauthorized access to protected information.
Recommendations
For BusyBox versions prior to 1.30.1, update to version 1.30.1 or later to resolve the issue.
As a temporary workaround, consider restricting access to the DHCP client, server, and relay components until a patch is available.
Exploit
Correção
Out of bounds Read
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Busybox
Suse
Ubuntu