Out of Bounds Read in BusyBox Affects DHCP Client and Server
CVE-2019-5747
7.5HIGH
What is CVE-2019-5747?
An out of bounds read vulnerability exists in BusyBox versions up to 1.30.0, specifically within the udhcp components, which are utilized by the DHCP client, server, and relay. This flaw may allow a remote attacker to exploit a crafted DHCP message to leak sensitive information from the stack. The issue stems from insufficient handling of a 4-byte length while decoding DHCP_SUBNET, and it is a continuation of an incomplete fix for a previous vulnerability. This vulnerability emphasizes the need for robust handling of network protocols to ensure data security.
