CVE-2019-5747: High severity Busybox Busybox vulnerability
An issue was discovered in BusyBox through 1.30.0. An out of bounds read in udhcp components (consumed by the DHCP client, server, and/or relay) might allow a remote attacker to leak sensitive information from the stack by sending a crafted DHCP message. This is related to assurance of a 4-byte length when decoding DHCPSUBNET. NOTE: this issue exists because of an incomplete fix for CVE-2018-20679.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2019-5747?
CVE-2019-5747 is a vulnerability in BusyBox through 1.30.0 that allows a remote attacker to leak sensitive information from the stack by sending a crafted DHCP message.
How severe is CVE-2019-5747?
CVE-2019-5747 has a severity rating of 7.5 (High).
How can I fix CVE-2019-5747?
To fix CVE-2019-5747, update to BusyBox version 1.27.2-2ubuntu5 or later.
Where can I find more information about CVE-2019-5747?
You can find more information about CVE-2019-5747 at the following references: <ul><li><a href='https://bugs.busybox.net/show_bug.cgi?id=11506' target='_blank'>https://bugs.busybox.net/show_bug.cgi?id=11506</a></li><li><a href='https://git.busybox.net/busybox/commit/?id=74d9f1ba37010face4bd1449df4d60dd84450b06' target='_blank'>https://git.busybox.net/busybox/commit/?id=74d9f1ba37010face4bd1449df4d60dd84450b06</a></li><li><a href='https://usn.ubuntu.com/3935-1/' target='_blank'>https://usn.ubuntu.com/3935-1/</a></li></ul>
What is the Common Weakness Enumeration (CWE) associated with CVE-2019-5747?
The Common Weakness Enumeration (CWE) associated with CVE-2019-5747 is CWE-125 (Out-of-bounds Read).