PT-2019-5460 · Busybox+2 · Busybox+2

Denys Vlasenko

·

Publicado

2019-01-09

·

Atualizado

2024-06-15

·

CVE-2019-5747

CVSS v2.0

7.8

Alta

VetorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions BusyBox versions prior to 1.30.1
Description An issue in the udhcp component of BusyBox might allow a remote attacker to leak sensitive information from the stack by sending a crafted DHCP message. This is due to an out of bounds read when decoding DHCP SUBNET, related to an incomplete fix for a previous issue. The vulnerability is associated with a buffer read beyond its boundaries in memory, potentially allowing an unauthorized access to protected information.
Recommendations For BusyBox versions prior to 1.30.1, update to version 1.30.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the DHCP client, server, and relay components until a patch is available.

Exploit

Correção

Out of bounds Read

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2020-03182
CVE-2019-5747
OPENSUSE-SU-2022:0135-1
OPENSUSE-SU-2022_0135-1
OPENSUSE-SU-2022_3959-1
OPENSUSE-SU-2024:11738-1
SUSE-SU-2022:0135-1
SUSE-SU-2022:0135-2
SUSE-SU-2022:3959-1
SUSE-SU-2022:4253-1
USN-3935-1

Produtos afetados

Busybox
Suse
Ubuntu