CVE-2023-42366: Medium severity Busybox Busybox vulnerability
Published Nov 27, 2023
·Updated
A heap-buffer-overflow was discovered in BusyBox v.1.36.1 in the nexttoken function at awk.c:1159.
Affected Software
6 affected componentsFixes available
Busybox Busybox=1.36.1
Microsoft cbl2 busybox 1.35.0-13
Microsoft azl3 busybox 1.36.1-9
Microsoft cbl2 busybox 1.35.0-13
Microsoft azl3 busybox 1.36.1-12
Microsoft cbl2 busybox 1.35.0-12
Event History
Nov 27, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Nov 20, 2024
Data Sourced
via Microsoft·08:00 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·08:00 AM
Affected Software
Updated
via Microsoft·08:00 AM
Affected Software
Updated
via Microsoft·08:00 AM
SeverityAffected Software
Updated
via Microsoft·08:00 AM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2023-42366?
The severity of CVE-2023-42366 is medium.
2
How does CVE-2023-42366 affect BusyBox?
CVE-2023-42366 affects BusyBox version 1.36.1.
3
Where can I find more information about CVE-2023-42366?
You can find more information about CVE-2023-42366 at https://bugs.busybox.net/show_bug.cgi?id=15874.
4
What is the Common Weakness Enumeration (CWE) of CVE-2023-42366?
The Common Weakness Enumeration (CWE) of CVE-2023-42366 is CWE-787.
5
How can I fix CVE-2023-42366?
There is currently no known fix for CVE-2023-42366. It is advised to follow the official security advisory for updates and patches from the vendor.