PT-2021-23606 · Busybox+3 · Busybox+3

Published

2021-11-09

·

Updated

2025-04-30

·

CVE-2021-42377

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Busybox (affected versions not specified)
Description The issue arises from an attacker-controlled pointer free in Busybox's hush applet, leading to a denial of service and possible code execution when a crafted shell command is processed. This is due to the shell mishandling the &&& string, potentially allowing for remote code execution under rare conditions of filtered command input.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-05993
CVE-2021-42377
MGASA-2021-0533
OPENSUSE-SU-2022:0135-1
OPENSUSE-SU-2022_0135-1
OPENSUSE-SU-2022_3959-1
OPENSUSE-SU-2024:11738-1
SUSE-SU-2022:0135-1
SUSE-SU-2022:0135-2
SUSE-SU-2022:3959-1
SUSE-SU-2022:4253-1

Affected Products

Busybox
Debian
Red Os
Suse