PT-2019-5460 · Busybox+2 · Busybox+2

Denys Vlasenko

·

Published

2019-01-09

·

Updated

2024-06-15

·

CVE-2019-5747

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions BusyBox versions prior to 1.30.1
Description An issue in the udhcp component of BusyBox might allow a remote attacker to leak sensitive information from the stack by sending a crafted DHCP message. This is due to an out of bounds read when decoding DHCP SUBNET, related to an incomplete fix for a previous issue. The vulnerability is associated with a buffer read beyond its boundaries in memory, potentially allowing an unauthorized access to protected information.
Recommendations For BusyBox versions prior to 1.30.1, update to version 1.30.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the DHCP client, server, and relay components until a patch is available.

Exploit

Fix

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-03182
CVE-2019-5747
OPENSUSE-SU-2022:0135-1
OPENSUSE-SU-2022_0135-1
OPENSUSE-SU-2022_3959-1
OPENSUSE-SU-2024:11738-1
SUSE-SU-2022:0135-1
SUSE-SU-2022:0135-2
SUSE-SU-2022:3959-1
SUSE-SU-2022:4253-1
USN-3935-1

Affected Products

Busybox
Suse
Ubuntu