CVE-2023-42363: Use After Free
Published Nov 27, 2023
·Updated
A use-after-free vulnerability was discovered in xasprintf function in xfuncsprintf.c:344 in BusyBox v.1.36.1.
Affected Software
7 affected componentsFixes available
debian/busybox<=1:1.30.1-6, <=1:1.35.0-4, <=1:1.36.1-9
Busybox Busybox=1.36.1
Microsoft cbl2 busybox 1.35.0-13
Microsoft azl3 busybox 1.36.1-7
Microsoft azl3 busybox 1.36.1-12
Microsoft cbl2 busybox 1.35.0-13
Microsoft cbl2 busybox 1.35.0-11
Remediation
Event History
Nov 27, 2023
CVE Published
12:00 AM
Data Sourced
12:00 AM
Description
Aug 14, 2024
Data Sourced
via Launchpad·09:47 PM
Description
Aug 18, 2024
Data Sourced
via Microsoft·07:00 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·07:00 AM
Affected Software
Updated
via Microsoft·07:00 AM
Description
Updated
via Microsoft·07:00 AM
DescriptionSeverity
Sep 15, 2024
Data Sourced
via Ubuntu·09:52 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is CVE-2023-42363?
CVE-2023-42363 is a use-after-free vulnerability discovered in the xasprintf function in BusyBox v.1.36.1.
2
What is the severity of CVE-2023-42363?
CVE-2023-42363 has a severity rating of medium (5.5).
3
How does CVE-2023-42363 affect BusyBox?
CVE-2023-42363 affects BusyBox version 1.36.1.
4
How can the use-after-free vulnerability in CVE-2023-42363 be exploited?
The use-after-free vulnerability in CVE-2023-42363 can be exploited by an attacker to execute arbitrary code or cause a denial-of-service condition.
5
Is there a fix available for CVE-2023-42363?
Yes, a fix for CVE-2023-42363 is available in the latest version of BusyBox.