CVE-2021-42375: Medium severity busybox vulnerability
An incorrect handling of a special element in Busybox's ash applet leads to denial of service when processing a crafted shell command, due to the shell mistaking specific characters for reserved characters. This may be used for DoS under rare conditions of filtered command input.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-42375?
CVE-2021-42375 is a vulnerability in Busybox's ash applet that leads to denial of service when processing a crafted shell command.
What is the severity of CVE-2021-42375?
The severity of CVE-2021-42375 is medium with a CVSS score of 5.5.
Which software versions are affected by CVE-2021-42375?
Busybox version 1.33.1, Fedora 33 and Fedora 34, Netapp Cloud Backup, Netapp Hci Management Node, Netapp Solidfire, Apple macOS Ventura, Apple macOS Big Sur, Apple macOS Monterey, Netapp H300e Firmware, Netapp H500e Firmware, Netapp H700e Firmware, and Apple macOS Monterey are affected.
How can I fix CVE-2021-42375?
To fix CVE-2021-42375, it is recommended to update Busybox to a patched version, apply the necessary software updates for affected operating systems, or follow the recommendations from the software vendors or distributors.
Where can I find more information about CVE-2021-42375?
More information about CVE-2021-42375 can be found at the following references: [Link1](https://claroty.com/team82/research/unboxing-busybox-14-vulnerabilities-uncovered-by-claroty-jfrog), [Link2](https://jfrog.com/blog/unboxing-busybox-14-new-vulnerabilities-uncovered-by-claroty-and-jfrog/), [Link3](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6T2TURBYYJGBMQTTN2DSOAIQGP7WCPGV/).