The security analysis of the BusyBox package identified 14 insignificant vulnerabilities.

Researchers from Claroty and JFrog published the results of a security audit for the BusyBox package, which is widely used in embedded devices and offers a set of standard UNIX utilities packaged as a single executable file. The audit uncovered 14 vulnerabilities, all of which have been addressed in the August release of BusyBox 1.34. Almost all of these issues are non-threatening and questionable in terms of applicability in real attacks, as they require utilities to be run with externally supplied arguments.

Notably, the vulnerability CVE-2021-42374 allows for a denial of service when handling a specially crafted compressed file with the unlzma utility, and if built with the CONFIG_FEATURE_SEAMLESS_LZMA option, also affects other BusyBox components including tar, unzip, rpm, dpkg, lzma, and man.

Vulnerabilities CVE-2021-42373, CVE-2021-42375, CVE-2021-42376, and CVE-2021-42377 can lead to denial of service but require the man, ash, and hush utilities to be executed with parameters set by the attacker. Vulnerabilities from CVE-2021-42378 to CVE-2021-42386 impact the awk utility and could potentially lead to code execution, but this requires the attacker to achieve the execution of a specific pattern in awk (the attacker needs to run awk with input data received from them in the first command-line argument).

Additionally, there is a vulnerability (CVE-2021-43523) in the uclibc and uclibc-ng libraries related to the lack of validation and sanitization of the domain name returned by the DNS server when accessing the functions gethostbyname(), getaddrinfo(), gethostbyaddr(), and getnameinfo(). For example, in response to a certain resolution request, a maliciously controlled DNS server could return hosts like ".attacker.com", and they would be returned unchanged to some program that may display them in its web interface without sanitization. The issue has been fixed in uclibc-ng release 1.0.39 by adding code to validate the returned data. domain names, implemented similarly to Glibc.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster