CVE-2018-20679: High severity Advantech Spectre RT ERT351 firmware Versions 5.1.3 and prior vulnerability
An issue was discovered in BusyBox before 1.30.0. An out of bounds read in udhcp components (consumed by the DHCP server, client, and relay) allows a remote attacker to leak sensitive information from the stack by sending a crafted DHCP message. This is related to verification in udhcpgetoption() in networking/udhcp/common.c that 4-byte options are indeed 4 bytes.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2018-20679?
CVE-2018-20679 is a vulnerability in BusyBox before version 1.30.0 that allows a remote attacker to leak sensitive information from the stack.
How severe is CVE-2018-20679?
CVE-2018-20679 has a severity rating of 7.5 (high).
What is the affected software?
The affected software is BusyBox before version 1.30.0 on various Ubuntu and Canonical Ubuntu Linux versions.
How can I fix CVE-2018-20679?
To fix CVE-2018-20679, update BusyBox to version 1.30.0 or later.
Where can I find more information about CVE-2018-20679?
You can find more information about CVE-2018-20679 at the following references: [1] [2] [3].