First published: Wed May 18 2022(Updated: )
A use-after-free in Busybox 1.35-x's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the copyvar function.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
BusyBox | =1.35.0 | |
Siemens Scalance SC622-2C Firmware | <3.0 | |
Siemens Scalance SC622-2C Firmware | ||
Siemens Scalance SC626-2C | <3.0 | |
Siemens Scalance SC626-2C Firmware | ||
Siemens Scalance SC632-2C Firmware | <3.0 | |
Siemens Scalance SC632-2C Firmware | ||
Siemens Scalance SC636-2C | <3.0 | |
Siemens SCALANCE SC636-2C | ||
Siemens Scalance SC642-2C | <3.0 | |
Siemens SCALANCE SC642-2C | ||
Siemens Scalance SC646-2C Firmware | <3.0 | |
Siemens SCALANCE SC646-2C (6GK5646-2GS00-2AC2) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-30065 is a use-after-free vulnerability in Busybox 1.35-x's awk applet that can lead to denial of service and possibly code execution when processing a crafted awk pattern in the copyvar function.
Busybox version 1.35.0 and Apple macOS Big Sur (up to exclusive version 3.0) are affected by CVE-2022-30065.
The severity of CVE-2022-30065 is high with a CVSS score of 7.8.
CVE-2022-30065 can be exploited by processing a crafted awk pattern in the copyvar function of Busybox 1.35-x's awk applet.
More information about CVE-2022-30065 can be found at the following references: [https://bugs.busybox.net/show_bug.cgi?id=14781](https://bugs.busybox.net/show_bug.cgi?id=14781) and [https://cert-portal.siemens.com/productcert/pdf/ssa-333517.pdf](https://cert-portal.siemens.com/productcert/pdf/ssa-333517.pdf)