Remote Code Execution Risk in Busybox's Hush Applet
CVE-2021-42377
9.8CRITICAL
What is CVE-2021-42377?
A vulnerability in the hush applet of Busybox can lead to denial of service and potential remote code execution through manipulated shell commands. The mishandling of the special '&&&' string by the shell creates an opportunity for attackers to exploit this weakness, especially in scenarios where input commands are filtered. This flaw could have significant security implications if exploited under the right conditions.
Affected Version(s)
busybox < 1.34.0
