CVE Vulnerabilities

CVE-2021-42375

Published: Nov 15, 2021 | Modified: Nov 07, 2023
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
1.9 LOW
AV:L/AC:M/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu

An incorrect handling of a special element in Busyboxs ash applet leads to denial of service when processing a crafted shell command, due to the shell mistaking specific characters for reserved characters. This may be used for DoS under rare conditions of filtered command input.

Affected Software

Name Vendor Start Version End Version
Busybox Busybox 1.33.1 (including) 1.33.1 (including)

References