Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Focus

#23491of 53,611
10Total CVSS
Vulnerabilities · 1
PT-2022-6884
10
2022-12-28
Busybox · Busybox · CVE-2022-48174
**Name of the Vulnerable Software and Affected Versions** busybox versions prior to 1.35 **Description** The issue is related to a stack overflow vulnerability in the ash.c file of busybox, which can be exploited to achieve arbitrary code execution. This vulnerability is associated with a buffer overflow in memory, allowing a remote attacker to execute arbitrary code using specially crafted data. The vulnerability can be executed from a command in the environment of the Internet of Vehicles. **Recommendations** For busybox versions prior to 1.35, update to version 1.35 or later to resolve the issue. As a temporary workaround, consider restricting the use of the ash.c component until a patch is available. Avoid using specially crafted data that could exploit the buffer overflow vulnerability in the ash.c file.