CVE-2023-42365: Use After Free
Published Nov 27, 2023
·Updated
A use-after-free vulnerability was discovered in BusyBox v.1.36.1 via a crafted awk pattern in the awk.c copyvar function.
Affected Software
7 affected componentsFixes available
debian/busybox<=1:1.30.1-6, <=1:1.35.0-4, <=1:1.36.1-9
Busybox Busybox=1.36.1
Microsoft cbl2 busybox 1.35.0-11
Microsoft azl3 busybox 1.36.1-12
Microsoft cbl2 busybox 1.35.0-13
Microsoft azl3 busybox 1.36.1-7
Microsoft cbl2 busybox 1.35.0-13
Remediation
Event History
Nov 27, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·11:15 PM
DescriptionSeverityWeaknessAffected Software
Aug 14, 2024
Data Sourced
via Launchpad·09:47 PM
Description
Aug 18, 2024
Data Sourced
via Microsoft·07:00 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·07:00 AM
Affected Software
Updated
via Microsoft·07:00 AM
DescriptionSeverity
Updated
via Microsoft·07:00 AM
Description
Sep 15, 2024
Data Sourced
via Ubuntu·09:52 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-42365?
The severity of CVE-2023-42365 is medium with a CVSS score of 5.5.
2
How does CVE-2023-42365 affect BusyBox?
CVE-2023-42365 affects BusyBox version 1.36.1.
3
What is the vulnerability in CVE-2023-42365?
CVE-2023-42365 is a use-after-free vulnerability in BusyBox's awk.c copyvar function.
4
How can I fix CVE-2023-42365?
To fix CVE-2023-42365, update BusyBox to a version that is not affected by the vulnerability.
5
Where can I find more information about CVE-2023-42365?
You can find more information about CVE-2023-42365 at the following link: [https://bugs.busybox.net/show_bug.cgi?id=15871](https://bugs.busybox.net/show_bug.cgi?id=15871).