CVE Vulnerabilities

CVE-2021-28831

Improper Handling of Exceptional Conditions

Published: Mar 19, 2021 | Modified: Nov 07, 2023
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
7.5 MODERATE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Ubuntu
LOW

decompress_gunzip.c in BusyBox through 1.32.1 mishandles the error bit on the huft_build result pointer, with a resultant invalid free or segmentation fault, via malformed gzip data.

Weakness

The product does not handle or incorrectly handles an exceptional condition.

Affected Software

Name Vendor Start Version End Version
Busybox Busybox 1.32.0 (including) 1.32.1 (including)
Busybox Ubuntu bionic *
Busybox Ubuntu devel *
Busybox Ubuntu esm-infra/xenial *
Busybox Ubuntu focal *
Busybox Ubuntu groovy *
Busybox Ubuntu hirsute *
Busybox Ubuntu impish *
Busybox Ubuntu jammy *
Busybox Ubuntu kinetic *
Busybox Ubuntu lunar *
Busybox Ubuntu precise/esm *
Busybox Ubuntu trusty *
Busybox Ubuntu trusty/esm *
Busybox Ubuntu upstream *
Busybox Ubuntu xenial *

References