Unrated severityNVD Advisory· Published Nov 15, 2021· Updated Aug 4, 2024
CVE-2021-42377
CVE-2021-42377
Description
An attacker-controlled pointer free in Busybox's hush applet leads to denial of service and possible code execution when processing a crafted shell command, due to the shell mishandling the &&& string. This may be used for remote code execution under rare conditions of filtered command input.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6T2TURBYYJGBMQTTN2DSOAIQGP7WCPGV/mitrevendor-advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UQXGOGWBIYWOIVXJVRKHZR34UMEHQBXS/mitrevendor-advisory
- claroty.com/team82/research/unboxing-busybox-14-vulnerabilities-uncovered-by-claroty-jfrogmitre
- jfrog.com/blog/unboxing-busybox-14-new-vulnerabilities-uncovered-by-claroty-and-jfrog/mitre
- security.netapp.com/advisory/ntap-20211223-0002/mitre
News mentions
0No linked articles in our index yet.