CVE Vulnerabilities

CVE-2021-42373

NULL Pointer Dereference

Published: Nov 15, 2021 | Modified: Nov 21, 2024
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
5.5 MODERATE
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Ubuntu
LOW

A NULL pointer dereference in Busyboxs man applet leads to denial of service when a section name is supplied but no page argument is given

Weakness

The product dereferences a pointer that it expects to be valid but is NULL.

Affected Software

Name Vendor Start Version End Version
Busybox Busybox 1.33.0 (including) 1.33.0 (including)
Busybox Busybox 1.33.1 (including) 1.33.1 (including)
Busybox Ubuntu trusty *
Busybox Ubuntu upstream *
Busybox Ubuntu xenial *

Potential Mitigations

References