Use-After-Free Vulnerability in BusyBox by BusyBox Project
CVE-2023-42365

5.5MEDIUM

Key Information:

Vendor

Busybox

Status
Vendor
CVE Published:
27 November 2023

What is CVE-2023-42365?

A use-after-free vulnerability has been identified in BusyBox v.1.36.1, posing potential security risks when a crafted awk pattern is utilized within the awk.c copyvar function. This flaw could lead to unexpected behavior, compromising the application's integrity and performance. It is crucial for users to remain vigilant and apply necessary patches to mitigate the risks associated with this vulnerability.

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.