CVE-2022-48174: Critical severity Busybox Busybox vulnerability
Last updated 14 August 2024
Other sources
There is a stack overflow vulnerability in ash.c:6030 in busybox before 1.35. In the environment of Internet of Vehicles, this vulnerability can be executed from command to arbitrary code execution.
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
busyboxto a version that resolves this vulnerability.Fixed in 1.35
Event History
Frequently Asked Questions
What is the vulnerability ID for this stack overflow vulnerability?
The vulnerability ID for this stack overflow vulnerability is CVE-2022-48174.
What is the severity of CVE-2022-48174?
The severity of CVE-2022-48174 is critical with a severity value of 9.8.
What is affected by CVE-2022-48174?
Busybox versions before 1.35.0 are affected by CVE-2022-48174.
How can this vulnerability be exploited?
This vulnerability can be exploited by executing a command to achieve arbitrary code execution.
Where can I find more information about CVE-2022-48174?
You can find more information about CVE-2022-48174 at the following references: - [Bugzilla](https://bugs.busybox.net/show_bug.cgi?id=15216) - [Launchpad](https://launchpad.net/bugs/cve/CVE-2022-48174) - [Git commit](https://git.busybox.net/busybox/commit/?id=d417193cf37ca1005830d7e16f5fa7e1d8a44209)