First published: Tue Jun 26 2018(Updated: )
Busybox contains a Missing SSL certificate validation vulnerability in The "busybox wget" applet that can result in arbitrary code execution. This attack appear to be exploitable via Simply download any file over HTTPS using "busybox wget https://compromised-domain.com/important-file".
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Busybox Busybox | <1.32.0 | |
debian/busybox | <=1:1.30.1-6<=1:1.35.0-4<=1:1.36.1-9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2018-1000500.
The severity of CVE-2018-1000500 is high with a severity value of 8.1.
The affected software for CVE-2018-1000500 is Busybox.
CVE-2018-1000500 can be exploited by simply downloading any file over HTTPS using "busybox wget" command.
No specific remedies are mentioned for CVE-2018-1000500 in the provided information.