Use-After-Free Vulnerability in BusyBox Affects Users
CVE-2023-42364

5.5MEDIUM

Key Information:

Vendor

Busybox

Status
Vendor
CVE Published:
27 November 2023

What is CVE-2023-42364?

The use-after-free vulnerability in BusyBox version 1.36.1 can be exploited by attackers to create a denial of service condition. This occurs through the manipulation of a crafted awk pattern within the awk.c evaluate function, allowing for unintended memory access and system instability. Users are urged to review their deployment configurations to mitigate potential risks.

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.