First published: Mon Nov 27 2023(Updated: )
A use-after-free vulnerability in BusyBox v.1.36.1 allows attackers to cause a denial of service via a crafted awk pattern in the awk.c evaluate function.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Busybox Busybox | =1.36.1 | |
debian/busybox | <=1:1.30.1-6<=1:1.35.0-4<=1:1.36.1-9 |
https://git.busybox.net/busybox/commit/editors/awk.c?id=0256e00a9d077588bd3a39f5a1ef7e2eaa2911e4
https://git.busybox.net/busybox/commit/editors/awk.c?id=fb08d43d44d1fea1f741fafb9aa7e1958a5f69aa
https://git.busybox.net/busybox/commit/editors/awk.c?id=38335df9e9f45378c3407defd38b5b610578bdda
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-42364 is a use-after-free vulnerability in BusyBox v.1.36.1 that allows attackers to cause a denial of service via a crafted awk pattern in the awk.c evaluate function.
This vulnerability can be exploited by using a crafted awk pattern in the evaluate function of the awk.c file in BusyBox v.1.36.1.
CVE-2023-42364 has a severity rating of medium.
CVE-2023-42364 affects BusyBox v.1.36.1.
At the moment, there is no known fix available for CVE-2023-42364. It is recommended to update to a version of BusyBox that is not affected by the vulnerability when it becomes available.