USN-6961-1: BusyBox vulnerabilities
It was discovered that BusyBox did not properly validate user input when performing certain arithmetic operations. If a user or automated system were tricked into processing a specially crafted file, an attacker could possibly use this issue to cause a denial of service, or execute arbitrary code. (CVE-2022-48174) It was discovered that BusyBox incorrectly managed memory when evaluating certain awk expressions. An attacker could possibly use this issue to cause a denial of service, or execute arbitrary code. This issue only affected Ubuntu 24.04 LTS. (CVE-2023-42363, CVE-2023-42364, CVE-2023-42365)
Affected Software
Event History
Child vulnerabilities
Contains the following vulnerabilities.
Frequently Asked Questions
What is the severity of USN-6961-1?
USN-6961-1 is classified as a high severity vulnerability due to improper user input validation in BusyBox.
How do I fix USN-6961-1?
To fix USN-6961-1, update BusyBox and its related packages to the versions specified in the advisory.
What is the impact of USN-6961-1?
Exploitation of USN-6961-1 can lead to a denial of service or possible remote code execution.
Which versions of BusyBox are affected by USN-6961-1?
USN-6961-1 affects several versions of BusyBox up to 1:1.36.1-6ubuntu3.1 and older in specified Ubuntu releases.
How can I check if I'm vulnerable to USN-6961-1?
Check the installed version of BusyBox on your Ubuntu system against the versions listed in the USN-6961-1 advisory.